Skip to content
IBMCVE-2026-14973

IBM Aspera Desktop App: path traversal

Critical9.3CVE-2026-14973 · Published Jul 28, 2026 · updated Aug 13, 2026

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

IBM advisory

Affected versions

PackageAffectedFixed in
Aspera Desktop App
Product
>= 1.0.5, <= 1.0.19No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More IBM advisories

All IBM
Advisory
IBM WebSphere Application Server: denial of service
High7.5Jul 28
IBM Aspera Faspex 5: insufficient session expiration
High8.2Jul 28
IBM WebSphere Application Server - Liberty: denial of service
High7.5Jul 28
IBM WebSphere Application Server: request smuggling
High8.7Jul 28
IBM WebSphere Application Server - Liberty: path traversal
High7.5Jul 28
IBM WebSphere Application Server: request smuggling
High8.7Jul 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.