rootpwn

critical · CVSS v3 9.1

CVE-2026-75878

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessio…

Description

IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
9.1
CVSS v4
EPSS

← All CVEs