Progress ShareFile vulnerabilities allow unauthenticated file exfiltration
Overview
Researchers from watchTowr have discovered two significant vulnerabilities in Progress ShareFile, specifically within the Storage Zones Controller (SZC) component of versions 5.x. The first vulnerability, identified as CVE-2026-2699, is an authentication bypass that could allow unauthorized users to access files. The second flaw, CVE-2026-2701, is a remote code execution vulnerability that could enable attackers to run arbitrary code on affected systems. These vulnerabilities pose a serious risk to organizations using ShareFile, as they could lead to unauthorized data access and potential exploitation. It is crucial for users to take immediate action to secure their systems against these vulnerabilities.
Key Takeaways
- Affected Systems: Progress ShareFile versions 5.x, specifically the Storage Zones Controller (SZC) component.
- Action Required: Users should update to the latest version of Progress ShareFile to patch these vulnerabilities.
- Timeline: Newly disclosed
Original Article Summary
Researchers at watchTowr identified an authentication bypass (CVE-2026-2699) and a remote code execution flaw (CVE-2026-2701) within the Storage Zones Controller (SZC) component of Progress ShareFile versions 5.x.
Impact
Progress ShareFile versions 5.x, specifically the Storage Zones Controller (SZC) component.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should update to the latest version of Progress ShareFile to patch these vulnerabilities. Additionally, organizations should review their access controls and ensure that only authorized personnel have access to sensitive files.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability.