ZeroHour

CVE-2026-19290

niche1

Unauthenticated Information Disclosure in IBM Sterling File Gateway 6.2.x

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

IBM Sterling File Gateway contains an improper access control flaw (CWE-284) that could allow a remote attacker to obtain sensitive information without any authentication or user interaction. The vulnerability affects the 6.2.x release streams from 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1, and is triggered by sending unauthenticated requests to an insufficiently protected interface or resource. An attacker gains read access to sensitive data (high confidentiality impact) but cannot modify data or cause denial of service, per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Organizations using these managed file transfer deployments for B2B data exchange are affected. The flaw is not in the CISA Known Exploited Vulnerabilities catalog and no public proof of concept or observed exploitation is known.

What to do: Apply IBM's fixed builds for the 6.2.0, 6.2.1, and 6.2.2 streams as described in the IBM security bulletin for this CVE. Until patched, restrict network access to Sterling File Gateway interfaces (UI, API, and HTTP-based endpoints) to trusted VPN/internal ranges and enforce authentication at a reverse proxy. Review access logs for unauthenticated requests to sensitive resources from unexpected sources to rule out prior data exposure.

Affected
IBM Sterling File Gateway
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed instances worldwide; total enterprise deployments in the thousands — Sterling File Gateway is enterprise managed-file-transfer middleware typically deployed by large organizations, and public internet scans historically show only a small exposed footprint of Sterling console endpoints, so the reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker to obtain sensitive information due to improper access control.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

IBM security advisory (AV26-922)

Canadian Cyber Centre relays IBM advisory for Langflow, MQ, and Sterling File Gateway flaws including MQ remote code execution (CVE-2026-13293).

Canadian Cyber Centre advisory AV26-922 relays IBM fixes for Langflow OSS (versions through 1.11.5 across release lines), IBM MQ (10.0.0.0 and 9.x LTS/CD through 9.4.5.1), and Sterling File Gateway (through 6.2.2.1). CVE-2026-13293 is a remote code execution flaw in IBM MQ Java messaging caused by an incomplete security scanner blocklist enabling network-based code execution. CVE-2026-19290 is an improper access control vulnerability in IBM Sterling File Gateway. Administrators are urged to review and apply the necessary updates.