What is CVE-2026-14973?
This CVE describes a vulnerability in IBM Aspera Desktop App versions 1.0.5 through 1.0.19 that allows files to be written outside the user's selected download destination. This could enable an attacker to create arbitrary files on the system. Users of affected versions should update to the latest version.
Azərbaycanca: Bu CVE, IBM Aspera Desktop App-in 1.0.5-dən 1.0.19-dək versiyalarında faylların istifadəçinin seçdiyi endirmə qovluğundan kənarda yazılmasına imkan verən zəifliyi təsvir edir. Bu, təcavüzkara sistemdə ixtiyari fayl yaratmağa şərait yarada bilər. Təsirə məruz qalan versiyaların istifadəçiləri proqramı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of the IBM Aspera Desktop App are affected by CVE-2026-14973?
Versions 1.0.5 through 1.0.19 are affected.
What can an attacker do by exploiting this vulnerability?
An attacker could create arbitrary files on the system because files can be written outside the user's selected download destination.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.