CVE-2026-9035
published 2026-05-27CVE-2026-9035: IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera…
PriorityP342medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.33%
24.6th percentile
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aspera_high-speed_transfer_endpoint | — | — |
| ibm | aspera_high-speed_transfer_endpoint | 3.7.4 – 4.4.6 | — |
| ibm | aspera_high-speed_transfer_server | — | — |
| ibm | aspera_high-speed_transfer_server | 3.7.4 – 4.4.6 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
IBM Aspera High-Speed Transfer Endpoint up to 4.4.7 FP1 Asperahttpd path traversal
vuldb·2026-05-27·CVSS 6.5
CVE-2026-9035 [MEDIUM] IBM Aspera High-Speed Transfer Endpoint up to 4.4.7 FP1 Asperahttpd path traversal
A vulnerability has been found in IBM Aspera High-Speed Transfer Endpoint and Aspera High-Speed Transfer Server up to 4.4.7 FP1 and classified as critical. The impacted element is an unknown function of the component Asperahttpd. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-9035. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-2qr9-h6wh-7p92: IBM Aspera High-Speed Transfer Endpoint 3
ghsa_unreviewed·2026-05-27
CVE-2026-9035 [MEDIUM] CWE-22 GHSA-2qr9-h6wh-7p92: IBM Aspera High-Speed Transfer Endpoint 3
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage of this vulnerability to access files in the server’s local storage that they should not have access to.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-27
Published