Information Disclosure Vulnerability in IBM Sterling File Gateway
IBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.
CVE search metadata
CVE search record: CVE-2026-19290. Severity: high. CVSS: 7.5. KEV: no. Product: Sterling File Gateway (6.2.0.0 - 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1). Brief: Information Disclosure Vulnerability in IBM Sterling File Gateway. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ibm-sterling-info-disclosure/
IBM Sterling File Gateway is affected by a security vulnerability identified as CVE-2026-19290, which stems from improper access control mechanisms. The vulnerability exists within specific versions of the application, including 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 through 6.2.1.2, and 6.2.2.0 through 6.2.2.1. This flaw permits a remote, unauthenticated attacker to bypass intended access restrictions and gain unauthorized access to sensitive information stored within the system. Given the nature of Sterling File Gateway as a secure file transfer solution, the exposure of data managed by this platform presents a significant risk to organizational confidentiality. The vulnerability carries a CVSS v3.1 base score of 7.5.
Impact
Successful exploitation of this vulnerability allows remote attackers to access sensitive data managed by IBM Sterling File Gateway without proper authorization. Organizations utilizing the affected versions in their file transfer workflows are at risk of data exfiltration and loss of regulatory compliance.
Recommendation
Prioritize the identification of all IBM Sterling File Gateway instances within the environment. Consult the official IBM security bulletin to obtain the patch release or security update that resolves CVE-2026-19290 for your specific deployment version. Ensure all internet-facing instances are restricted from unauthorized network access until the vendor-supplied patches are successfully applied.
Mitigations
Patch IBM Sterling File Gateway to a version not listed in the affected range.
CVE-2026-19290