Description
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Published: 2026-09-18
Score: 9.1 Critical
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product VersionAPARRemediation & FixIBM Sterling File Gateway6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49865Apply 6.2.0.6_2, 6.2.1.2_1 or 6.2.2.1_1 The IIM versions 6.2.1.2_1 and 6.2.2.1_1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container versions of 6.2.1.2_1 and 6.2.2.1_1 are available in IBM Entitled Registry * cp.icr.io/cp/ibm-sfg for IBM Sterling File Gateway For 6.2.0.6_2, contact the support

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Title IBM Sterling File Gateway is Vulnerable to Authentication Bypass
First Time appeared Ibm
Ibm sterling File Gateway
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.6_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-18T19:22:17.649Z

Reserved: 2026-08-18T12:47:31.992Z

Link: CVE-2026-75878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:21.363

Modified: 2026-09-18T20:17:21.363

Link: CVE-2026-75878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses