CVE-2026-11980
Awaiting Analysis
Awaiting Analysis - Queue
Arbitrary Code Execution in IBM Aspera Desktop App
Vulnerability report for CVE-2026-11980, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-30
Last updated on: 2026-07-31
Assigner: IBM Corporation
Description
Description
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | aspera_desktop_app | From 1.0.5 (inc) to 1.0.19 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-242 | The product calls a function that can never be guaranteed to work safely. |