CVE-2026-75878
IBM Sterling File Gateway authentication bypass via unvalidated SSO header (CVE-2026-75878)
IBM Sterling File Gateway 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 to 6.2.1.2, and 6.2.2.0 to 6.2.2.1 has a critical authentication bypass via an unvalidated SSO header. A remote attacker can obtain a fully authenticated session. IBM has published an advisory.
What happened
IBM Sterling File Gateway contains an authentication bypass, described as improper authentication (CWE-287). Because the product accepts an SSO header without validating it, a remote attacker can send a request that results in a fully authenticated session. The vulnerability is scored 9.1 under CVSS 3.1: network attack vector, low complexity, no privileges, no user interaction, high confidentiality impact, high integrity impact and no availability impact.
The CVE record does not list the vulnerability as exploited, it is not included in CISA's KEV catalogue, and no public disclosure is recorded. IBM has not stated whether exploitation has occurred.
Who is affected
Affected releases are IBM Sterling File Gateway 6.2.0.0 to 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. Because the attack is network-based and requires no prior credentials or user interaction, any affected instance reachable from an untrusted network should be treated as exposed until it is confirmed to be on a fixed release.
What to do now
- Confirm the running version. If it is in the affected ranges, treat the instance as immediately exposed and do not leave it reachable from untrusted networks.
- Review IBM's advisory at https://www.ibm.com/support/pages/node/7287497 for the corrected release for your version branch. IBM records that a fix is available, but the data supplied here does not state the fixed version numbers.
- Apply the vendor fix as soon as possible. If deployment is delayed, restrict network access to trusted internal systems or known partner addresses and remove direct internet exposure.
- IBM's advisory data does not contain a workaround. While containment is in place, review successful logins for sessions that do not correspond to expected SSO flows.
Beyond the patch
A network-reachable authentication bypass on a file gateway is an exposure and trust-boundary problem, not just a patch item. Virtual CISO Services (vCISO) helps keep internet-facing services and open ports under continuous exposure review, and Implementation & Assessment Services tests authentication assumptions such as SSO header handling before they become an emergency. Patch first; then make sure the next exposed service is found before it is named in an advisory.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Sterling File Gateway | 6.2.0.0 – ≤ 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 | No fixed version listed yet |