CVE-2026-2699
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
Vulnerabilità ed exploit · Attacco ad app web
Progress ShareFile Storage Zones Controller (SZC) nella branch 5.x presenta due vulnerabilità ad alta gravità: un bypass di autenticazione (CVE-2026-2699) e un’esecuzione remota di codice (CVE-2026-2701). Il bypass di autenticazione consente agli attaccanti di accedere all’interfaccia di amministrazione senza credenziali. Questo accesso permette loro di manipolare segreti e configurazioni, abilitando la falla RCE per distribuire webshell ed esfiltrare file dalle Storage Zones gestite dal cliente.
3 fonti · 3 apr
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
CVSS 9.1 CRITICAL: authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
SecurityWeek
Critical ShareFile Flaws Lead to Unauthenticated RCE
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.
originaleCybersecurity Dive
Researchers warn of critical flaws in Progress ShareFile
Attackers could chain vulnerabilities together, leading to configuration changes or remote code execution.
originaleBleepingComputer
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
originalePart of the PlainSec briefing for 2026-04-04
Every edition of this story: Catena RCE non autenticata espone dati dei clienti in ShareFile Storage Zones