IBM Aspera Enterprise WebApps 1.0.0
IBM Aspera Enterprise WebApps could let a local attacker bypass container protections. That may expose data, allow changes, or disrupt services outside the container.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 1.0.6
- Affected versions
- 1.0.0 through 1.0.5
- Weakness
- CWE-269Improper Privilege Management
- Exploit likelihood
- 0.15% in 30 daysEPSS, higher than 4% of known flaws
- Affects
- Aspera Enterprise WebApps
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-75802ENISA vulnerability database
How it works
- The attacker must first have local access with limited privileges.
- The container permits system calls that should be restricted.
- This can let the attacker escape the container boundary.
- The supplied advisory does not specify the exact escape path.
What to do
Check the installed Aspera Enterprise WebApps version and compare it with IBM's security bulletin. Versions 1.0.0 through 1.0.5 are in scope.
Upgrade IBM Aspera Enterprise WebApps to version 1.0.6 through IBM's security bulletin.
Technical details
CVE-2026-75777 is a local privilege-management flaw with a CVSS 3.1 score of 8.8. It requires low privileges but no user interaction, and can affect confidentiality, integrity, and availability beyond the container.
Severity breakdown
- Attack vector Local Needs local access to the machine
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286738 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-75777 third party advisory vdb entry
- cvefeed.io · CVE-2026-75777 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-75777