CVE-2026-2699
PoC moderateUnauthenticated RCE in Progress ShareFile Storage Zones Controller
CVE-2026-2699 is an improper access control flaw (CWE-284) in customer-managed Progress ShareFile Storage Zones Controller (SZC) that lets an unauthenticated attacker reach restricted configuration pages over the network. Because the issue is reachable pre-authentication with no user interaction and low complexity (AV:N/AC:L/PR:N), an attacker needs only network access to an exposed controller. Successful abuse allows the attacker to change system configuration and potentially escalate to full remote code execution, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 9.8). Any organization running its own customer-managed SZC deployment is affected; the Progress/ShareFile-hosted cloud service itself is not the flaw, though Progress has taken precautionary emergency action (disabling ShareFile accounts and urging customers to shut down controllers) amid an active security threat per press reports. A public proof-of-concept exploit is available (watchTowr Labs), the flaw carries a very high EPSS of 59.5% (99th percentile) indicating strong likelihood of exploitation within 30 days, and it is not yet listed in CISA KEV.
What to do: Apply the vendor patch as soon as possible per the Progress security bulletin (the fixed version is not specified in the available data). As interim mitigation, restrict unauthenticated internet access to the SZC configuration interface (e.g., firewall or reverse-proxy rules) and consider temporarily taking the controller offline if immediate patching is not possible, as Progress has advised. Review logs for unauthenticated requests to configuration pages and signs of configuration changes or follow-on command execution.
| Progress ShareFile Storage Zones Controller (customer-managed deployments) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
- Vendors
- progress
- Products
- sharefile storage zones controller
- Weakness
- CWE-284, CWE-698
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H