CRITICAL🇵🇱 Wersja polska

CVE-2026-2701

CVSS 9.1v3.1pub. 2026-04-02upd. 2026-04-21

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

🤖 AI Analysis
How it works

The vulnerability results from a lack of proper validation of uploaded files (CWE-434 — unrestricted file upload) and the possibility of system command injection (CWE-78) or malicious code execution (CWE-94). An authenticated attacker uploads a specially crafted file to the server and then causes it to be executed by the application, resulting in arbitrary code execution in the server context.

Impact

An attacker can gain full control of the server, including reading and modifying data, installing additional software (e.g., backdoor), and potentially moving laterally across the internal network (lateral movement).

Mitigation & patch

Apply patches available from the vendor according to the references: https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26. Additionally, it is recommended to restrict access to the file upload interface to trusted users only and monitor server activity for suspicious operations.

Who is affected

Progress Sharefile Storage Zones Controller — versions indicated in the vendor references (https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Progress Sharefile Storage Zones Controller

    APP
    Progress
    5.0.0 – 5.12.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2026-2699CRITICAL9.8PL ✓same product

Auth Bypass i RCE w Progress ShareFile Storage Zones Controller

CVE-2026-16137HIGH7.2same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perf...

CVE-2026-16138HIGH8.0same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted...

CVE-2026-16139HIGH7.2same product

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administ...

CVE-2026-15724HIGH8.7PL ✓same product

Path traversal w Progress ShareFile Storage Zones Controller