Description
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Problem types
CWE-698: Execution After Redirect (EAR)
CWE-284: Improper Access Control
Product status
Any version
Credits
Sonny of watchTowr
h4x0r_dz
References
github.com/.../watchTowr-vs-Progress-ShareFile-CVE-2026-2699
docs.sharefile.com/...oller/5-0/security-vulnerability-feb26