CVE-2026-75878
IBM Sterling File Gateway is Vulnerable to Authentication Bypass
Description
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
INFO
Published Date :
Sept. 18, 2026, 7:22 p.m.
Last Modified :
Sept. 18, 2026, 7:22 p.m.
Remotely Exploit :
Yes !
Source :
ibm
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 9a959283-ebb5-44b6-b705-dcc2bbced522 |
Solution
- Validate the SSO header to ensure proper authentication.
- Apply vendor patches or updates when available.
- Review and enforce authentication controls.
- Monitor for unauthorized access attempts.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-75878 vulnerability anywhere in the article.