Description
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Published: 2026-09-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Product VersionAPARRemediation & FixIBM Sterling File Gateway6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1IT49865Apply 6.2.0.6_2, 6.2.1.2_1 or 6.2.2.1_1 The IIM versions 6.2.1.2_1 and 6.2.2.1_1 are available on  Fix Central http://www-933.ibm.com/support/fixcentral/swg/selectFixes .  The container versions of 6.2.1.2_1 and 6.2.2.1_1 are available in IBM Entitled Registry * cp.icr.io/cp/ibm-sfg for IBM Sterling File Gateway For 6.2.0.6_2, contact the support

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
Title IBM Sterling File Gateway is Vulnerable to Authentication Bypass
First Time appeared Ibm
Ibm sterling File Gateway
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_file_gateway:6.2.0.6_1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm sterling File Gateway
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Ibm Sterling File Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-19T14:11:40.461Z

Reserved: 2026-08-18T12:47:31.992Z

Link: CVE-2026-75878

cve-icon Vulnrichment

Updated: 2026-09-19T14:07:35.305Z

cve-icon NVD

Status : Received

Published: 2026-09-18T20:17:21.363

Modified: 2026-09-19T15:17:00.883

Link: CVE-2026-75878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:30:06Z

Weaknesses