CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
References
Link Resource
https://www.ibm.com/support/pages/node/7280939 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:ibm:aspera:*:*:*:*:desktop:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-28 21:17

Updated : 2026-08-13 14:04


NVD link : CVE-2026-14973

Mitre link : CVE-2026-14973

CVE.ORG link : CVE-2026-14973


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

ibm

  • aspera

apple

  • macos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')