CVE-2026-75777
nicheContainer Escape via Unrestricted System Calls in IBM Aspera Enterprise WebApps
IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 permit unrestricted system calls inside their containers, meaning the container's isolation protections are not fully enforced (improper privilege management, CWE-269). An attacker who already has low-privileged local access within a WebApps container can issue system calls that should be restricted and break out of the container boundary. Because the CVSS scope is changed (S:C) with high impact to confidentiality, integrity, and availability, a successful escape can expose the underlying host and potentially other workloads running on it. Only organizations running IBM Aspera Enterprise with the WebApps component at versions 1.0.0 through 1.0.5 are affected. The flaw is not currently listed in CISA's KEV catalog and no public proof-of-concept or in-the-wild exploitation is known.
What to do: Inventory Aspera Enterprise deployments for the WebApps component and identify any running versions 1.0.0-1.0.5, then upgrade to a fixed release beyond 1.0.5 once IBM publishes one (check the IBM PSIRT advisory for CVE-2026-75777 for the exact fixed version). Until patched, prioritize hosts where WebApps containers run alongside other workloads, since a container escape there exposes the host and neighboring containers, and restrict local access to the containers. As this requires pre-existing low-privileged local access, exposure is limited to environments where users or other processes can execute inside the WebApps container.
| IBM Aspera Enterprise WebApps | 1.0.0 through 1.0.5 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.