Back to overview

CVE-2026-2699

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Metadata

CVE ID
CVE-2026-2699
State
PUBLISHED
Assigner
ProgressSoftware
Reserved
2026-02-18 16:18 UTC
Published
2026-04-02 13:04 UTC
Last updated
2026-04-08 15:25 UTC
Primary CWE
CWE-698
CWE-698: Execution After Redirect (EAR)
Vendor / Product
Progress / ShareFile Storage Zones Controller
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Progress ShareFile Storage Zones Controller 0 ≤ 5.12.3
Weakness (CWE)
CWESourceDescription
CWE-284 cna CWE-284: Improper Access Control
CWE-698 cna CWE-698: Execution After Redirect (EAR)
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview