CRITICAL🇵🇱 Wersja polska

CVE-2026-2699

CVSS 9.8v3.1pub. 2026-04-02upd. 2026-04-21

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

🤖 AI Analysis
How it works

An attacker without any authentication can gain access to protected configuration pages of the Storage Zones Controller component. Lack of proper access control (CWE-284) allows bypassing authorization mechanisms and directly accessing protected administrative resources. After gaining access to the configuration panel, the attacker can modify system settings in a way that leads to remote code execution on the server.

Impact

An attacker can gain full control of the server through arbitrary code execution (RCE), and can also modify system configuration, which may result in breaches of confidentiality, integrity, and availability of data stored in the ShareFile environment.

Mitigation & patch

Apply patches available from the vendor in accordance with references — details available at: https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26. Until updates are deployed, it is recommended to restrict network access to the Storage Zones Controller administration panel exclusively to trusted IP addresses.

Who is affected

Progress ShareFile Storage Zones Controller (Customer Managed) — versions indicated in the vendor references (security documentation from February 2026).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Progress Sharefile Storage Zones Controller

    APP
    Progress
    5.0.0 – 5.12.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2026-2701CRITICAL9.1PL ✓same product

RCE w Progress Sharefile Storage Zones Controller — upload złośliwego pliku

CVE-2026-16137HIGH7.2same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perf...

CVE-2026-16138HIGH8.0same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted...

CVE-2026-16139HIGH7.2same product

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administ...

CVE-2026-15724HIGH8.7PL ✓same product

Path traversal w Progress ShareFile Storage Zones Controller