CVE-2026-2699
Citrix ShareFile StorageZones Controller vulnerability analysis and mitigation

Overview

CVE-2026-2699 is an improper access control vulnerability (authentication bypass) in Progress Software's Customer Managed ShareFile Storage Zones Controller (SZC) that allows unauthenticated remote attackers to access restricted configuration pages, modify system configuration, and potentially achieve remote code execution. It affects ShareFile SZC versions 5.0.0 through 5.12.3 (i.e., all versions before 5.12.4). The vulnerability was published on April 2, 2026, with a patch simultaneously released. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, ShareFile Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control) and CWE-698 (Execution After Redirect / EAR). The root cause is that the SZC web application fails to properly enforce authentication on restricted configuration pages — an unauthenticated HTTP request can reach sensitive administrative endpoints that should require valid credentials. The EAR component means the application may issue a redirect response (e.g., HTTP 302) to an authentication page but still execute privileged server-side logic before the redirect completes, allowing an attacker to interact with restricted functionality without ever authenticating. This vulnerability can be chained with CVE-2026-2701 (an authenticated RCE via malicious file upload) to form a complete pre-authentication remote code execution attack chain (watchTowr Labs, BleepingComputer).

Impact

Successful exploitation allows an unauthenticated network attacker to access and modify system configuration on the ShareFile Storage Zones Controller, and when chained with CVE-2026-2701, to execute arbitrary code on the underlying server without any credentials. This can result in full compromise of the SZC host, unauthorized access to all files stored in the customer-managed storage zone (including sensitive organizational data), and potential lateral movement within the enterprise network. The confidentiality, integrity, and availability impacts are all rated High (ShareFile Advisory, watchTowr Labs).

Exploitability

A detection/scanner tool (not a full exploit) was published by watchTowr Labs on April 2, 2026, which sends HTTP requests to test whether a ShareFile SZC instance is vulnerable to CVE-2026-2699 but explicitly does not perform zone takeover or chain with RCE (watchTowr GitHub). A separate PoC repository (CVE-2026-2699 by 0xBlackash) appeared on April 7, 2026. Exploitation has been reported by multiple sources including BleepingComputer, and Shadowserver began scanning for vulnerable instances. A Nuclei detection template was also merged into the ProjectDiscovery nuclei-templates repository. The EPSS score is approximately 0.099 (~9.9%), and no CISA KEV catalog listing was identified in the available data (BleepingComputer, Feedly).

Exploitation steps

  1. Reconnaissance: Use Shodan, Censys, or similar tools to identify internet-facing Progress ShareFile Storage Zones Controller instances running versions 5.0.0–5.12.3. The watchTowr scanner tool can be used to confirm vulnerability.
  2. Authentication Bypass (CVE-2026-2699): Send a crafted HTTP request directly to a restricted administrative configuration endpoint on the SZC web interface. Due to the EAR flaw, the server executes privileged logic before issuing a redirect to the login page, granting access to configuration functionality without credentials.
  3. Configuration Manipulation: Use the unauthorized access to read or modify system configuration settings on the SZC, which may include storage paths, credentials, or upload handling settings.
  4. Chaining with RCE (CVE-2026-2701): Leverage the configuration access gained in step 2–3 to satisfy the authentication precondition for CVE-2026-2701, then upload a malicious file (e.g., a web shell) through the file upload functionality to achieve remote code execution on the server.
  5. Post-Exploitation: With code execution on the SZC host, exfiltrate stored files, establish persistence, or pivot to other internal network resources (watchTowr Labs, BleepingComputer).

Indicators of compromise

  • Network: Unexpected HTTP requests (especially GET or POST) to administrative/configuration endpoints on the SZC web interface from unauthenticated or unknown source IPs; outbound connections from the SZC server to unknown external hosts following such requests.
  • Logs: IIS or web server access logs showing requests to restricted configuration pages returning HTTP 200 responses (rather than 302/401/403) from unauthenticated sessions; repeated probing of configuration endpoints from a single IP.
  • File System: Presence of unexpected web shells or script files (e.g., .aspx, .php) in the SZC web root or upload directories; newly created or modified files in the SZC installation directory by the web server process account.
  • Process: Unusual child processes spawned by the IIS worker process (w3wp.exe), such as cmd.exe, powershell.exe, or network utilities (curl, certutil); unexpected scheduled tasks or services created on the SZC host.
  • Scanning Activity: Shadowserver and other scanning organizations have been probing for vulnerable instances — defenders may observe increased scanning traffic against SZC management ports (BleepingComputer, watchTowr GitHub).

Mitigation and workarounds

Progress Software has released ShareFile Storage Zones Controller version 5.12.4 as the patched release; all customers running versions 5.0.0 through 5.12.3 should upgrade immediately (ShareFile Advisory). As an interim measure, restrict network access to the SZC management interface to trusted administrative IP ranges only using firewall rules or network segmentation. Monitor for suspicious configuration changes and unauthorized access attempts to the management interface. The CIS Security Advisory also recommends prioritizing this patch given the critical severity and pre-authentication exploitation potential (CIS Advisory).

Community reactions

The vulnerability received significant attention from the security community immediately after disclosure on April 2, 2026. watchTowr Labs published a detailed technical write-up and detection tool, and the research was widely shared on Reddit (r/netsec, r/blueteamsec, r/cybersecurity), Bluesky, and Mastodon/Infosec.exchange (watchTowr Labs). BleepingComputer, Cybersecurity Dive, SC World, and The Hacker News all covered the vulnerability, emphasizing the pre-authentication RCE chain risk (BleepingComputer). Shadowserver announced active scanning for vulnerable instances. Arctic Wolf, Field Effect, SOCRadar, and runZero published independent advisories and blog posts. The HIPAA Journal highlighted the risk to healthcare organizations using ShareFile for sensitive file sharing (HIPAA Journal). The Emerging Threats ruleset was updated on April 7, 2026 to include detection rules for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Citrix ShareFile StorageZones Controller vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2699CRITICAL9.8
  • Citrix ShareFile StorageZones Controller logoCitrix ShareFile StorageZones Controller
  • cpe:2.3:a:citrix:sharefile_storagezones_controller
NoYesApr 02, 2026
CVE-2023-24489CRITICAL9.8
  • Citrix ShareFile StorageZones Controller logoCitrix ShareFile StorageZones Controller
  • cpe:2.3:a:citrix:sharefile_storagezones_controller
YesYesJul 10, 2023
CVE-2021-22941CRITICAL9.8
  • Citrix ShareFile StorageZones Controller logoCitrix ShareFile StorageZones Controller
  • cpe:2.3:a:citrix:sharefile_storagezones_controller
YesYesSep 23, 2021
CVE-2026-2701HIGH8.8
  • Citrix ShareFile StorageZones Controller logoCitrix ShareFile StorageZones Controller
  • cpe:2.3:a:citrix:sharefile_storagezones_controller
NoYesApr 02, 2026
CVE-2021-22932HIGH7.5
  • Citrix ShareFile StorageZones Controller logoCitrix ShareFile StorageZones Controller
  • cpe:2.3:a:citrix:sharefile_storagezones_controller
NoYesAug 16, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management