← Vulnerability feed

Vulnerability record · CVE-2023-24489 · published 10 July 2023

CVE-2023-24489: Citrix ShareFile Storage Zones Controller improper access control

Citrix · Sharefile Storage Zones Controller

The customer-managed ShareFile storage zones controller contains an improper access control flaw that lets an unauthenticated attacker remotely compromise the controller. Because the controller handles file storage for the ShareFile deployment, compromise exposes the data and infrastructure it manages. The record does not specify the exact vulnerable code path or affected versions beyond the product name.

9.8 CVSS 3.1 Critical CISA KEV since 16 Aug 2023 EPSS 97% · top 0.1% CWE-284 · Improper access control
9.8CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, active exploitation per CISA KEV, and a near-maximum EPSS score make this an urgent patch.

What it is

The customer-managed ShareFile storage zones controller contains an improper access control flaw that lets an unauthenticated attacker remotely compromise the controller. Because the controller handles file storage for the ShareFile deployment, compromise exposes the data and infrastructure it manages. The record does not specify the exact vulnerable code path or affected versions beyond the product name.

Impact

An unauthenticated attacker can remotely compromise the storage zones controller, gaining high confidentiality, integrity and availability impact over that system and the stored content it serves.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description confirms remote exploitation by an unauthenticated attacker.

Exploitation

Listed in CISA KEV since 2023-08-16 with a 2023-09-06 remediation due date, and EPSS gives a 30-day probability of 0.97343 (99.894th percentile), indicating active exploitation. No ransomware campaign use is recorded.

What to do

  • Apply the Citrix security update for CVE-2023-24489 per vendor advisory CTX559517; if the advisory link is broken, obtain the fixed build through Citrix support.
  • If patching is not possible, follow CISA KEV guidance and discontinue use of the affected storage zones controller.
  • Restrict network access to the storage zones controller so it is not exposed to untrusted networks.
  • Monitor Citrix guidance for any interim configuration mitigations and apply them until the patch is in place.

Detection

  • Review storage zones controller logs for unexpected or anomalous requests, especially unauthenticated access attempts and unusual administrative actions.
  • Hunt for signs of post-exploitation activity on the controller host, such as new processes, web shells, or unexpected outbound connections.
  • Alert on network traffic to the controller from untrusted sources and on deviations from its normal request patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-24489 to the Known Exploited Vulnerabilities catalog on 16 August 2023 as "Citrix Content Collaboration ShareFile Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 6 September 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-24489 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2023-24489), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.