criticalOther

IBM Aspera Faspex 5 Unquoted Shell Interpolation Remote Code Execution

First seen Jul 29, 2026 · Updated Jul 29, 2026 · CVSS 9.1

asperafaspexrcefile-transferunquoted-shellauthenticated-attackeragent-relevant

A critical vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 allows a remote authenticated attacker to execute arbitrary code via unquoted shell interpolation. With a CVSS score of 9.1, exploitation could lead to full compromise of the file transfer server and any systems or credentials it interfaces with.

Technical Analysis

The vulnerability stems from improper input sanitization where shell commands are constructed using unquoted string interpolation, allowing an authenticated attacker to inject arbitrary shell metacharacters or commands that are executed with the privileges of the Faspex service process. Because Faspex is often deployed as a managed file transfer hub integrated with backend automation, API tokens, and downstream processing pipelines, successful exploitation could grant attackers a foothold to pivot into connected infrastructure. The requirement for authentication lowers the immediate risk from anonymous internet-wide scanning but does not mitigate insider threats or attackers who obtain low-privilege credentials via phishing or credential stuffing. Organizations that route AI agent workflows or RAG ingestion pipelines through Faspex for automated file intake (e.g., agents pulling datasets or documents transferred via Aspera) face risk of code execution on the host that could expose API keys, service credentials, or manipulate files feeding into agent pipelines, making this relevant to agent-adjacent infrastructure security.

Affected Systems

IBM Aspera Faspex 5, versions 5.0.0 through 5.0.15.4 (all deployment configurations exposing the Faspex web/API service to authenticated users)

Indicators of Compromise

  • No public IOCs available at this time; monitor Faspex application logs for anomalous shell command execution, unexpected child processes spawned by the Faspex service, and unusual outbound connections from the Faspex host.

Remediation Steps

  1. 1

    Apply Vendor Patch

    Upgrade to the IBM-released fixed version of Aspera Faspex 5 as soon as it is available; consult IBM's security bulletin for the specific patched release.

  2. 2

    Restrict Authenticated Access

    Limit and audit user accounts with Faspex authentication access, enforce MFA, and rotate credentials for accounts with elevated privileges.

  3. 3

    Network Segmentation

    Isolate Faspex servers from sensitive internal networks, credential stores, and AI agent/RAG pipeline infrastructure to limit lateral movement if compromised.

  4. 4

    Enhanced Monitoring

    Deploy host-based monitoring for unexpected shell process spawning from the Faspex application and enable detailed logging/alerting on the file transfer service.

  5. 5

    Credential Rotation

    Rotate any API keys, tokens, or credentials that may be accessible to or stored on the Faspex host, especially those used by connected automation or agent systems.

CVE / Advisory IDs

CVE-2026-14958

Industries Most Exposed

TechnologyMedia & EntertainmentFinancial ServicesHealthcareGovernmentManufacturing

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.