IBM Aspera Faspex 5 Session Mgmt Flaw 5.0.05.0.15.4
CVE-2026-14996 Published on July 28, 2026
Multiple vulnerabilities in IBM Aspera Faspex
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Vulnerability Analysis
CVE-2026-14996 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Products Associated with CVE-2026-14996
Want to know whenever a new CVE is published for IBM Aspera Faspex 5? stack.watch will email you.
Affected Versions
IBM Aspera Faspex 5:- Version 5.0.0, <= 5.0.15.4 is affected.