CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-39920

CVSS 9.3v4.0pub. 2026-04-24

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.

🤖 AI Analysis
How it works

The attacker connects remotely to the Apache Axis2 administrative interface, which is accessible over the network and configured with default credentials. After authenticating using these default credentials, the attacker uploads a malicious Java archive (JAR) as a web service. Subsequently, using SOAP requests to the deployed service, the attacker executes arbitrary commands on the host server. The vulnerability results from two weaknesses: an unsecured default configuration (CWE-1188) and the use of weak or default authentication credentials (CWE-1391).

Impact

The attacker gains the ability to execute arbitrary operating system commands on the server with the privileges of the service process, which can lead to complete system takeover, data theft, and further lateral movement within the network.

Mitigation & patch

BridgeHead FileStore should be updated to version 24A or later. Additionally, regardless of the update, default credentials for the Apache Axis2 administrative module must be changed immediately, and network access to the administrative interface should be restricted to trusted IP addresses only using firewall or network rules.

Who is affected

BridgeHead FileStore in versions prior to 24A (released in early 2024)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References