Vulnerabilities · 165 days ago

Unauthenticated RCE Chain Exposes Customer Data in ShareFile Storage Zones

Progress ShareFile Storage Zones Controller (SZC) in branch 5.x has two high-severity vulnerabilities: an authentication bypass (CVE-2026-2699) and a remote code execution (CVE-2026-2701). The auth bypass lets attackers access the admin interface without credentials. This access allows them to manipulate secrets and configuration, enabling the RCE flaw to deploy webshells and exfiltrate files from customer-managed Storage Zones.

This chain turns what would normally require authentication into a pre-auth attack, exposing internal or third-party cloud storage where sensitive documents reside. The vendor patched both flaws in ShareFile 5.12.4 on March 10. Any SZC deployment on branch 5.x should be patched immediately and audited for signs of compromise, as attackers can reach custodian-owned data without valid credentials.

CVE-2026-2699

NVD KEV

CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.

CVE-2026-2701

NVD KEV

CVSS 9.1 CRITICAL: authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Timeline

Sources

3 sources covering this story

Entities

Part of the PlainSec briefing for 2026-04-04

Editions

Related stories