critical · CVSS v3 9.1
CVE-2026-75878
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessio…
Description
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 9.1
- CVSS v4
- —
- EPSS
- —