Progress ShareFile Storage Zones Controller - Authentication Bypass
CVE-2026-2699
Verified
Description
Customer Managed ShareFile Storage Zones Controller (SZC) contains an authentication bypass (Execution After Redirect) that allows unauthenticated attackers to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Severity
Critical
CVSS Score
9.8
Exploit Probability
3%
Affected Product
sharefile_storage_zones_controller
Published Date
April 6, 2026
Template Author
dhiyaneshdk
CVE-2026-2699.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-2699
CWE ID:
cwe-284
References
https://github.com/watchtowrlabs/watchTowr-vs-Progress-ShareFile-CVE-2026-2699https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26
Remediation Steps
Update ShareFile Storage Zones Controller to version 5.12.4 or later.