CVE-2026-2699 is a critical vulnerability affecting Customer Managed ShareFile Storage Zones Controller (SZC). It allows an unauthenticated attacker to access restricted configuration pages, potentially leading to system configuration changes and remote code execution. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and requires no user interaction or authentication, enabling full compromise of confidentiality, integrity, and availability. While no public exploit code is currently available in common databases, the vulnerability is on an "Active" hot list and has garnered significant community and media attention, including discussions of a pre-authentication RCE chain. This indicates a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.12.4CPE matchmatch criteria | cpe:2.3:a:progress:sharefile_storage_zones_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.