
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2699 is an improper access control vulnerability (authentication bypass) in Progress Software's Customer Managed ShareFile Storage Zones Controller (SZC) that allows unauthenticated remote attackers to access restricted configuration pages, modify system configuration, and potentially achieve remote code execution. It affects ShareFile SZC versions 5.0.0 through 5.12.3 (i.e., all versions before 5.12.4). The vulnerability was published on April 2, 2026, with a patch simultaneously released. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, ShareFile Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control) and CWE-698 (Execution After Redirect / EAR). The root cause is that the SZC web application fails to properly enforce authentication on restricted configuration pages — an unauthenticated HTTP request can reach sensitive administrative endpoints that should require valid credentials. The EAR component means the application may issue a redirect response (e.g., HTTP 302) to an authentication page but still execute privileged server-side logic before the redirect completes, allowing an attacker to interact with restricted functionality without ever authenticating. This vulnerability can be chained with CVE-2026-2701 (an authenticated RCE via malicious file upload) to form a complete pre-authentication remote code execution attack chain (watchTowr Labs, BleepingComputer).
Successful exploitation allows an unauthenticated network attacker to access and modify system configuration on the ShareFile Storage Zones Controller, and when chained with CVE-2026-2701, to execute arbitrary code on the underlying server without any credentials. This can result in full compromise of the SZC host, unauthorized access to all files stored in the customer-managed storage zone (including sensitive organizational data), and potential lateral movement within the enterprise network. The confidentiality, integrity, and availability impacts are all rated High (ShareFile Advisory, watchTowr Labs).
A detection/scanner tool (not a full exploit) was published by watchTowr Labs on April 2, 2026, which sends HTTP requests to test whether a ShareFile SZC instance is vulnerable to CVE-2026-2699 but explicitly does not perform zone takeover or chain with RCE (watchTowr GitHub). A separate PoC repository (CVE-2026-2699 by 0xBlackash) appeared on April 7, 2026. Exploitation has been reported by multiple sources including BleepingComputer, and Shadowserver began scanning for vulnerable instances. A Nuclei detection template was also merged into the ProjectDiscovery nuclei-templates repository. The EPSS score is approximately 0.099 (~9.9%), and no CISA KEV catalog listing was identified in the available data (BleepingComputer, Feedly).
.aspx, .php) in the SZC web root or upload directories; newly created or modified files in the SZC installation directory by the web server process account.w3wp.exe), such as cmd.exe, powershell.exe, or network utilities (curl, certutil); unexpected scheduled tasks or services created on the SZC host.Progress Software has released ShareFile Storage Zones Controller version 5.12.4 as the patched release; all customers running versions 5.0.0 through 5.12.3 should upgrade immediately (ShareFile Advisory). As an interim measure, restrict network access to the SZC management interface to trusted administrative IP ranges only using firewall rules or network segmentation. Monitor for suspicious configuration changes and unauthorized access attempts to the management interface. The CIS Security Advisory also recommends prioritizing this patch given the critical severity and pre-authentication exploitation potential (CIS Advisory).
The vulnerability received significant attention from the security community immediately after disclosure on April 2, 2026. watchTowr Labs published a detailed technical write-up and detection tool, and the research was widely shared on Reddit (r/netsec, r/blueteamsec, r/cybersecurity), Bluesky, and Mastodon/Infosec.exchange (watchTowr Labs). BleepingComputer, Cybersecurity Dive, SC World, and The Hacker News all covered the vulnerability, emphasizing the pre-authentication RCE chain risk (BleepingComputer). Shadowserver announced active scanning for vulnerable instances. Arctic Wolf, Field Effect, SOCRadar, and runZero published independent advisories and blog posts. The HIPAA Journal highlighted the risk to healthcare organizations using ShareFile for sensitive file sharing (HIPAA Journal). The Emerging Threats ruleset was updated on April 7, 2026 to include detection rules for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."