Skip to content

CVE-2026-75878

IBM Sterling File Gateway authentication bypass via unvalidated SSO header (CVE-2026-75878)

Critical 9.1 Vendor: IBM Published

IBM Sterling File Gateway 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 to 6.2.1.2, and 6.2.2.0 to 6.2.2.1 has a critical authentication bypass via an unvalidated SSO header. A remote attacker can obtain a fully authenticated session. IBM has published an advisory.

What happened

IBM Sterling File Gateway contains an authentication bypass, described as improper authentication (CWE-287). Because the product accepts an SSO header without validating it, a remote attacker can send a request that results in a fully authenticated session. The vulnerability is scored 9.1 under CVSS 3.1: network attack vector, low complexity, no privileges, no user interaction, high confidentiality impact, high integrity impact and no availability impact.

The CVE record does not list the vulnerability as exploited, it is not included in CISA's KEV catalogue, and no public disclosure is recorded. IBM has not stated whether exploitation has occurred.

Who is affected

Affected releases are IBM Sterling File Gateway 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. Because the attack is network-based and requires no prior credentials or user interaction, any affected instance reachable from an untrusted network should be treated as exposed until it is confirmed to be on a fixed release.

What to do now

  1. Confirm the running version. If it is in the affected ranges, treat the instance as immediately exposed and do not leave it reachable from untrusted networks.
  2. Review IBM's advisory at https://www.ibm.com/support/pages/node/7287497 for the corrected release for your version branch. IBM records that a fix is available, but the data supplied here does not state the fixed version numbers.
  3. Apply the vendor fix as soon as possible. If deployment is delayed, restrict network access to trusted internal systems or known partner addresses and remove direct internet exposure.
  4. IBM's advisory data does not contain a workaround. While containment is in place, review successful logins for sessions that do not correspond to expected SSO flows.

Beyond the patch

A network-reachable authentication bypass on a file gateway is an exposure and trust-boundary problem, not just a patch item. Virtual CISO Services (vCISO) helps keep internet-facing services and open ports under continuous exposure review, and Implementation & Assessment Services tests authentication assumptions such as SSO header handling before they become an emergency. Patch first; then make sure the next exposed service is found before it is named in an advisory.

Affected and fixed versions

ProductAffectedFixed in
Sterling File Gateway6.2.0.0 – ≤ 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.