Vulnerability record · CVE-2026-2699 · published 2 April 2026
CVE-2026-2699: Progress ShareFile Storage Zones Controller improper access control
Progress · Sharefile Storage Zones Controller
Customer Managed ShareFile Storage Zones Controller (SZC) exposes restricted configuration pages to unauthenticated attackers due to improper access control (CWE-284). Because those pages control system configuration, reaching them can lead to configuration changes and potential remote code execution.
Description
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and a public exploit make this an urgent patch target.
What it is
Customer Managed ShareFile Storage Zones Controller (SZC) exposes restricted configuration pages to unauthenticated attackers due to improper access control (CWE-284). Because those pages control system configuration, reaching them can lead to configuration changes and potential remote code execution.
Impact
An unauthenticated attacker can read and alter restricted configuration, potentially achieving remote code execution on the controller. That gives full compromise of the SZC host and the storage zone it manages.
Attack surface
Reachable over the network via the SZC web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed SZC instance is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is 0.595 (99th percentile) and a public proof-of-concept exploit is referenced from watchTowr Labs, indicating active public exploitation capability. No ransomware usage is documented.
What to do
- Apply the vendor fix from the Progress ShareFile SZC security advisory for the affected 5.x line; patch first.
- Restrict network access to SZC management interfaces to trusted admin networks; do not expose them to the internet.
- Rotate credentials and secrets stored or configured on the SZC host, since configuration pages were reachable unauthenticated.
- Review SZC configuration and logs for unauthorized changes made before patching.
- Monitor vendor advisory for updated guidance if a patch is not yet deployable.
Detection
- Alert on unauthenticated or anomalous requests to SZC restricted configuration endpoints, especially from unexpected source IPs.
- Monitor SZC configuration files and admin settings for unexpected modifications.
- Hunt for post-exploitation activity on the SZC host such as new processes, web shells, or outbound connections.
- Correlate SZC access logs with authentication logs to find configuration page access without a valid session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26 | Vendor Advisory |
| https://github.com/watchtowrlabs/watchTowr-vs-Progress-ShareFile-CVE-2026-2699 | ExploitThird Party Advisory |
Track CVE-2026-2699 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-2699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.