← Vulnerability feed

Vulnerability record · CVE-2026-2699 · published 2 April 2026

CVE-2026-2699: Progress ShareFile Storage Zones Controller improper access control

Progress · Sharefile Storage Zones Controller

Customer Managed ShareFile Storage Zones Controller (SZC) exposes restricted configuration pages to unauthenticated attackers due to improper access control (CWE-284). Because those pages control system configuration, reaching them can lead to configuration changes and potential remote code execution.

9.8 CVSS 3.1 Critical EPSS 3.2% · top 12.4% CWE-284 · Improper access controlCWE-698 · CWE-698
9.8CVSS 3.1 base score
3.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, high EPSS, and a public exploit make this an urgent patch target.

What it is

Customer Managed ShareFile Storage Zones Controller (SZC) exposes restricted configuration pages to unauthenticated attackers due to improper access control (CWE-284). Because those pages control system configuration, reaching them can lead to configuration changes and potential remote code execution.

Impact

An unauthenticated attacker can read and alter restricted configuration, potentially achieving remote code execution on the controller. That gives full compromise of the SZC host and the storage zone it manages.

Attack surface

Reachable over the network via the SZC web interface with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed SZC instance is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.595 (99th percentile) and a public proof-of-concept exploit is referenced from watchTowr Labs, indicating active public exploitation capability. No ransomware usage is documented.

What to do

  • Apply the vendor fix from the Progress ShareFile SZC security advisory for the affected 5.x line; patch first.
  • Restrict network access to SZC management interfaces to trusted admin networks; do not expose them to the internet.
  • Rotate credentials and secrets stored or configured on the SZC host, since configuration pages were reachable unauthenticated.
  • Review SZC configuration and logs for unauthorized changes made before patching.
  • Monitor vendor advisory for updated guidance if a patch is not yet deployable.

Detection

  • Alert on unauthenticated or anomalous requests to SZC restricted configuration endpoints, especially from unexpected source IPs.
  • Monitor SZC configuration files and admin settings for unexpected modifications.
  • Hunt for post-exploitation activity on the SZC host such as new processes, web shells, or outbound connections.
  • Correlate SZC access logs with authentication logs to find configuration page access without a valid session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-2699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-2701Progress ShareFile Storage Zones Controller authenticated file upload RCEAn authenticated user can upload a malicious file to the Progress ShareFile Storage Zones Controller and execute it on the server, resulting in remot…EPSS 3.4%analysed8.7CVE-2026-15724Progress sharefile storage zones controller improper input validation vulnerabilityIn Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …EPSS 0.52%8.0CVE-2026-16138Progress sharefile storage zones controller deserialization of untrusted data vulnerabilityIn Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wr…EPSS 0.83%7.2CVE-2026-16137Progress sharefile storage zones controller path traversal vulnerabilityIn Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo…EPSS 0.74%7.2CVE-2026-16139Progress sharefile storage zones controller improper input validation vulnerabilityIn Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation i…EPSS 0.94%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2026-2699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.