CVE-2026-2699

CRITICAL EXPLOITED NUCLEI

EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-2699 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including 0xBlackash, watchtowrlabs. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains only a minimal README with the CVE identifier and no exploit code or technical details. It is a placeholder with no functional content.

Description

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Exploits (2)

nomisec STUB
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-2699

The repository contains only a minimal README with the CVE identifier and no exploit code or technical details. It is a placeholder with no functional content.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
mistral-large-3 · analyzed Apr 08, 2026 Full analysis →
nomisec SCANNER
by watchtowrlabs · poc
https://github.com/watchtowrlabs/watchTowr-vs-Progress-ShareFile-CVE-2026-2699

This repository contains a Python script that scans for CVE-2026-2699, an authentication bypass vulnerability in Progress ShareFile. The tool sends a GET request to the `/ConfigService/Admin.aspx` endpoint and checks the response to determine if the target is likely vulnerable.

Classification
Scanner 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Progress ShareFile Storage Zones Controller < 5.12.4
No auth needed
Prerequisites: Network access to the target ShareFile instance
mistral-large-3 · analyzed Apr 07, 2026 Full analysis →

Nuclei Templates (1)

Progress ShareFile Storage Zones Controller - Authentication Bypass
CRITICALVERIFIEDby DhiyaneshDk
Shodan: title:"ShareFile Storage Server"
FOFA: title=="ShareFile Storage Server"

Scores

CVSS v3 9.8
EPSS 0.5839
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-07-10
CWE
CWE-284 CWE-698
Status published
Products (2)
Progress/ShareFile Storage Zones Controller < 5.12.3
progress/sharefile_storage_zones_controller 5.0.0 - 5.12.4
Published Apr 02, 2026
Tracked Since Apr 02, 2026