CVE-2026-2699
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 59.51%
- CWE
- CWE-698, CWE-284
- Published
- 2026-04-02
- Last modified
- 2026-04-08
Affected products
- Progress ShareFile Storage Zones Controller
Weakness type
Related vulnerabilities
- CVE-2026-16323 — Authentication Bypass via Execution After Redirect in FuyaSoft's Architect Panel Web Management Panel
- CVE-2026-61407 — Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient...
- CVE-2026-58455 — Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
- CVE-2026-10271 — a4m4 Student-Management-System Admin Endpoint admin redirect
- CVE-2026-3264 — go2ismail Free-CRM Administrative redirect
- CVE-2026-3262 — go2ismail Asp.Net-Core-Inventory-Order-Management-System Administrative redirect
- CVE-2025-8350 — Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS
- CVE-2025-6967 — Authentication Bypass in Sarman Soft's CMS