Sceawere

Vulnerability Detail

CVE-2026-75792UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Sterling Secure Proxy Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
IBM
Product
Sterling Secure Proxy
Attack Type
CWE-285 Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative user interface components due to client-side authorization bypass.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-14T21:17:25.720Z",
  "pubdate": "2026-09-14T21:17:25.720Z",
  "executiveSummary": "This vulnerability involves a client-side authorization bypass within the administrative user interface of IBM Sterling Secure Proxy.\nThe flaw allows a remote, authenticated attacker to gain unauthorized visibility into administrative interface components that should otherwise be restricted based on the user's assigned privilege level.\nAffected products include IBM Sterling Secure Proxy versions 6.2.0.0 through 6.2.1.2.\nThe security risk is categorized as a failure in access control enforcement, where the application relies on client-side logic to determine visibility of interface elements.\nAn attacker possessing valid credentials, even with limited privileges, can leverage this bypass to expose sensitive administrative workflows or data that the current session should not be authorized to view.\nThe vulnerability does not require complex exploit chains; however, it necessitates existing authenticated access to the application. This represents a significant risk to administrative integrity and configuration privacy, as it permits unauthorized information disclosure within the management console.",
  "technicalDetails": "The vulnerability resides within the administrative console of IBM Sterling Secure Proxy, specifically affecting how the application enforces authorization constraints during the rendering and navigation of the user interface.\nThe root cause of this issue is an improper implementation of access control mechanisms where the application utilizes client-side logic—specifically, browser-side rendering instructions or conditional visibility attributes—to restrict access to administrative functions. Because the authorization check is performed on the client side rather than enforced via server-side verification of session permissions during API requests, the integrity of the UI becomes dependent on the client's adherence to the expected state.\nAn authenticated attacker can exploit this by manipulating the client-side environment, such as modifying DOM elements, intercepting and altering UI configuration payloads, or directly navigating to administrative component endpoints that the front-end application attempted to hide. When the client attempts to access these components, the server fails to adequately validate whether the authenticated user possesses the necessary administrative authorization level to view or interact with the requested components.\nThe attack flow proceeds as follows: First, the attacker establishes a valid, low-privileged authenticated session with the IBM Sterling Secure Proxy interface. Second, the attacker identifies the URI endpoints or DOM structures corresponding to administrative UI components that are normally hidden from their user profile. Third, by bypassing the client-side constraints (e.g., changing display attributes or forced URL navigation), the attacker forces the browser to render the sensitive UI components. Finally, since the backend does not enforce secondary authorization checks at the functional level for these UI components, the administrative data is served to the unauthorized user.\nThe impact of this vulnerability is primarily unauthorized information disclosure. By accessing these administrative components, an attacker may view system configurations, network topology details, or potentially other sensitive metadata exposed through the administrative dashboard. This disclosure aids in reconnaissance, allowing the attacker to understand the proxy's architecture and identify further potential attack vectors or vulnerabilities within the environment. This vulnerability affects versions 6.2.0.0 through 6.2.1.2, highlighting a critical need for moving authorization logic from the client-side presentation layer to a robust server-side enforcement model."
}
CVE-2026-75792: IBM Sterling Secure Proxy Authorization Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere