CVE-2026-2699
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
Vulnerabilità · 179 giorni fa
Progress ShareFile Storage Zones Controller (SZC) nella branch 5.x presenta due vulnerabilità ad alta gravità: un bypass di autenticazione (CVE-2026-2699) e un’esecuzione remota di codice (CVE-2026-2701). Il bypass di autenticazione consente agli attaccanti di accedere all’interfaccia di amministrazione senza credenziali. Questo accesso permette loro di manipolare segreti e configurazioni, abilitando la falla RCE per distribuire webshell ed esfiltrare file dalle Storage Zones gestite dal cliente.
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
CVSS 9.1 CRITICAL: authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
3 fonti che coprono questa storia
Critical ShareFile Flaws Lead to Unauthenticated RCE
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.
Researchers warn of critical flaws in Progress ShareFile
Attackers could chain vulnerabilities together, leading to configuration changes or remote code execution.
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile, an enterprise-grade secure file transfer solution, can be chained to enable unauthenticated file exfiltration from affected environments.
Part of the PlainSec briefing for 2026-04-04