CVE-2026-11980CWE-242

CVE-2026-11980

High · published July 30, 2026

CVSS v3.1
7.3
EPSS
0%
Percentile
3.0
In the wild
Unconfirmed
What it is

IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00132 · 3.0th percentile
Weakness
CWE-242 · Use of Inherently Dangerous Function
Published
2026-07-30T19:16Z
Affected products (1)
ProductVersionsFixed in
ibm/aspera≥ 1.0.5, ≤ 1.0.19
References (1)
EPSS history
Timeline
  • 30 JUL 14:16Z
    Code execution in IBM Desktop App
    cvelistv5