Back to overview

CVE-2026-14973

CRITICAL
9.3
CVSS 3.1
Description
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Metadata

CVE ID
CVE-2026-14973
State
PUBLISHED
Assigner
ibm
Reserved
2026-07-07 16:44 UTC
Published
2026-07-28 20:31 UTC
Last updated
2026-07-28 20:31 UTC
Primary CWE
CWE-22
CWE-22 Improper Limitation of a Pathname to a Restricted Dir…
Vendor / Product
IBM / Aspera Desktop App
Sources
cve.org  ·  NVD

Severity & Metrics

9.3 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected products (1)
VendorProductPlatformVersions
IBM Aspera Desktop App 1.0.5 ≤ 1.0.19
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Back to overview