← Vulnerability feed

Vulnerability record · CVE-2021-22941 · published 23 September 2021

CVE-2021-22941: Citrix ShareFile storage zones controller improper access control

Citrix · Sharefile Storagezones Controller

Citrix ShareFile storage zones controller before 5.11.20 contains an improper access control flaw (CWE-284) that can let an unauthenticated attacker remotely compromise the controller. Because the controller sits in the storage path for ShareFile data, a compromise exposes the file storage infrastructure rather than a single user account.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 54% · top 1.0% CWE-284 · Improper access control
9.8CVSS 3.1 base score, v2 10.0
54%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated remote compromise, KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch target.

What it is

Citrix ShareFile storage zones controller before 5.11.20 contains an improper access control flaw (CWE-284) that can let an unauthenticated attacker remotely compromise the controller. Because the controller sits in the storage path for ShareFile data, a compromise exposes the file storage infrastructure rather than a single user account.

Impact

An unauthenticated attacker can remotely compromise the storage zones controller, gaining high confidentiality, integrity and availability impact on that host. In practice this means control of the component that brokers access to stored ShareFile data.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed storage zones controller instance is in scope.

Exploitation

Listed in CISA KEV since 2022-03-25 with known ransomware campaign use, and EPSS 30-day probability is about 0.536 (98.9th percentile), indicating active exploitation is expected. The vendor advisory reference is tagged as a broken link, so consult CISA KEV for the required action.

What to do

  • Upgrade Citrix ShareFile storage zones controller to 5.11.20 or later as instructed by the vendor advisory.
  • If immediate patching is not possible, remove the controller from direct internet exposure and restrict access to trusted networks.
  • Verify the controller is not reachable from untrusted networks and review firewall or load balancer rules for unintended exposure.
  • Rotate credentials and secrets used by the storage zones controller after patching, in case of prior compromise.
  • Monitor CISA KEV for updated guidance and confirm remediation against the listed due date.

Detection

  • Search web and proxy logs for anomalous requests to storage zones controller endpoints from unauthenticated or unexpected source IPs.
  • Review controller and host logs for unexpected process creation, file writes, or configuration changes around the controller service.
  • Hunt for signs of post-exploitation on controller hosts, including new accounts, scheduled tasks, or outbound connections to unfamiliar hosts.
  • Inventory all storage zones controller instances and confirm version is 5.11.20 or later.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22941 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Citrix ShareFile Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22941 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22891Citrix sharefile storagezones controller missing authorization vulnerabilityA missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow un…EPSS 1.1%7.5CVE-2021-22932Citrix sharefile storagezones controller missing encryption vulnerabilityAn issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryptio…EPSS 0.41%7.5CVE-2020-8982Citrix sharefile storagezones controller path traversal vulnerabilityAn unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the mo…EPSS 27%7.5CVE-2020-8983Citrix sharefile storagezones controller path traversal vulnerabilityAn arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.…EPSS 4.6%7.5CVE-2020-7473Citrix sharefile storagezones controller path traversal vulnerabilityIn certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of …EPSS 14%4.3CVE-2018-16969Citrix sharefile storagezones controller information exposure vulnerabilityCitrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message.EPSS 1.1%3.1CVE-2018-16968Citrix sharefile storagezones controller path traversal vulnerabilityCitrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.EPSS 1.1%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed

Source: NIST National Vulnerability Database (record CVE-2021-22941), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.