Home

Description

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

PUBLISHED Reserved 2026-02-18 | Published 2026-04-02 | Updated 2026-04-03 | Assigner ProgressSoftware




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-434: Unrestricted Upload of File with Dangerous Type

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

Any version
affected

Credits

Piotr Bazydlo of watchTowr finder

References

docs.sharefile.com/...oller/5-0/security-vulnerability-feb26 vendor-advisory

cve.org (CVE-2026-2701)

nvd.nist.gov (CVE-2026-2701)

Download JSON