CVE-2026-2699
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
Vulnerabilities & Exploits · Web App Attack
Progress ShareFile Storage Zones Controller (SZC) in branch 5.x has two high-severity vulnerabilities: an authentication bypass (CVE-2026-2699) and a remote code execution (CVE-2026-2701). The auth bypass lets attackers access the admin interface without credentials. This access allows them to manipulate secrets and configuration, enabling the RCE flaw to deploy webshells and exfiltrate files from customer-managed Storage Zones.
This chain turns what would normally require authentication into a pre-auth attack, exposing internal or third-party cloud storage where sensitive documents reside. The vendor patched both flaws in ShareFile 5.12.4 on March 10. Any SZC deployment on branch 5.x should be patched immediately and audited for signs of compromise, as attackers can reach custodian-owned data without valid credentials.
3 sources · Apr 3
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
CVSS 9.1 CRITICAL: authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
SecurityWeek
Critical ShareFile Flaws Lead to Unauthenticated RCE
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.
originalCybersecurity Dive
Researchers warn of critical flaws in Progress ShareFile
Attackers could chain vulnerabilities together, leading to configuration changes or remote code execution.
originalBleepingComputer
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
originalPart of the PlainSec briefing for 2026-04-04
Every edition of this story: Unauthenticated RCE Chain Exposes Customer Data in ShareFile Storage Zones