You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
WatchTowr Labs discovered and chained two vulnerabilities in Progress ShareFile's Storage Zone Controller (branch 5.x) to achieve pre-authenticated remote code execution. CVE-2026-2699 is an authentication bypass caused by CWE-698 (Execution After Redirect) — the .NET Redirect() call uses a 'false' boolean flag, meaning page
Table of contents
What is Progress ShareFile?What Are We Rambling About Today?Dissecting The ShareFile Storage Zone ControllerThere’s No Authentication Bypass Here? WT-2026-0006 (CVE-2026-2699) - Authentication Bypass VulnerabilityOk, But, What?Onwards To RCEYou're In The Danger Zone!WT-2026-0007 (CVE-2026-2701) - Post-Auth Remote Code ExecutionControlling the Upload PathUploading WebshellDetection Artifact GeneratorTimelineGain early access to our research, and understand your exposure, with the watchTowr PlatformSort: