Vulnerability record · CVE-2026-2701 · published 2 April 2026
CVE-2026-2701: Progress ShareFile Storage Zones Controller authenticated file upload RCE
Progress · Sharefile Storage Zones Controller
An authenticated user can upload a malicious file to the Progress ShareFile Storage Zones Controller and execute it on the server, resulting in remote code execution. The flaw combines unrestricted file upload with code and OS command injection, so a low-privileged account is enough to run code on the host. This matters because it turns ordinary authenticated access into full server compromise.
Description
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (99th percentile) make this a serious authenticated RCE, though it is not in KEV and requires a valid account.
What it is
An authenticated user can upload a malicious file to the Progress ShareFile Storage Zones Controller and execute it on the server, resulting in remote code execution. The flaw combines unrestricted file upload with code and OS command injection, so a low-privileged account is enough to run code on the host. This matters because it turns ordinary authenticated access into full server compromise.
Impact
An attacker with a valid low-privileged account gains remote code execution on the Storage Zones Controller, giving high impact to confidentiality, integrity and availability of the host and any data it handles.
Attack surface
Reached over the network via the application's file upload functionality; the CVSS vector shows PR:L and UI:N, so a valid authenticated account is required but no user interaction beyond the upload is needed.
Exploitation
Not listed in CISA KEV and no public exploit references are given, but EPSS is 0.54539 (99th percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Apply the vendor security update for ShareFile Storage Zones Controller per the Progress advisory.
- Restrict upload permissions and review which accounts can submit files to the controller.
- Enforce strict file type and content validation on uploads, and store uploaded files outside executable paths.
- Run the controller with least privilege and isolate it from other systems to limit post-exploitation reach.
- Monitor the vendor advisory for updated guidance and interim workarounds.
Detection
- Alert on file uploads that land in web-accessible or executable directories on the controller.
- Monitor for unexpected child processes spawned by the controller's web or application service.
- Review authentication logs for low-privileged accounts performing uploads followed by execution activity.
- Baseline and alert on new or modified executable files in upload and web root paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26 | Vendor Advisory |
Track CVE-2026-2701 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-2701), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.