¡¾Îó²îͨ¸æ¡¿Progress ShareFile Ô¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2026-2701)

Ðû²¼Ê±¼ä 2026-04-10

Ò»¡¢Îó²î¸ÅÊö


Îó²îÃû³Æ

Progress ShareFile Ô¶³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2026-2701

Îó²îÀàÐÍ

RCE

·¢Ã÷ʱ¼ä

2026-4-10

Îó²îÆÀ·Ö

9.1

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

¸ß

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

²»ÐèÒª

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷


Progress ShareFileÊÇÒ»¿îÆóÒµ¼¶Çå¾²Îļþ´«ÊäÓëЭ×÷ƽ̨£¬£¬£¬Ö§³ÖÎļþ¹²Ïí¡¢Êý¾ÝÍøÂç¡¢µç×ÓÊðÃû¼°Ê¹ÃüÖÎÀíµÈ¹¦Ð§¡£¡£¡£ÆäStorage Zone Controller×é¼þÔÊÐíÆóÒµÔÚÍâµØ»ò×Ô½ç˵´æ´¢ÇéÐÎÖÐÍйÜÊý¾Ý£¬£¬£¬Í¬Ê±Í¨¹ýShareFile SaaSƽ̨¾ÙÐÐͳһ»á¼û¿ØÖÆÓëÖÎÀí£¬£¬£¬ÆÕ±éÓ¦ÓÃÓÚ¶ÔÊý¾ÝÖ÷ȨºÍºÏ¹æÒªÇó½Ï¸ßµÄ×éÖ¯¡£¡£¡£


2026Äê4ÔÂ8ÈÕ£¬£¬£¬918²©ÌìÌÃÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄ£¨VSRC£©¼à²âµ½Progress ShareFile±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2026-2701£©£¬£¬£¬Í¬Ê±»¹±£´æÉí·ÝÈÏÖ¤ÈÆ¹ýÎó²î£¨CVE-2026-2699£©£¬£¬£¬¶þÕß¿É×éºÏʹÓÃÐγÉδÊÚȨԶ³Ì´úÂëÖ´Ðй¥»÷Á´¡£¡£¡£ÆäÖУ¬£¬£¬CVE-2026-2699Ô´ÓÚASP.NETÓ¦ÓùýʧʹÓÃResponse.Redirect(..., false)£¬£¬£¬ÔÚÖØ¶¨ÏòºóδÖÕÖ¹Ò³ÃæÖ´ÐУ¬£¬£¬µ¼ÖÂδÈÏÖ¤Óû§¿ÉÈÆ¹ýÉí·ÝÑéÖ¤»á¼ûºǫ́¹¦Ð§£»£»£» £»£»£»ÔÚ´Ë»ù´¡ÉÏ£¬£¬£¬CVE-2026-2701ÓÉÓÚϵͳÔڴ洢·¾¶ÉèÖü°ÎļþÉÏ´«½âѹÂß¼­ÖÐȱ·¦ÓÐÓÃÇå¾²ÏÞÖÆ£¬£¬£¬ÔÊÐí¹¥»÷Õß½«ÎļþдÈëWebĿ¼²¢Ö´ÐС£¡£¡£¹¥»÷ÕßÎÞÐèÉí·ÝÈÏÖ¤¼´¿Éͨ¹ý½á¹¹ÇëÇóÐÞ¸ÄϵͳÉèÖ㬣¬£¬²¢Á¬ÏµÎļþÉÏ´«Óë½âѹ¹¦Ð§Ð´Èë¶ñÒâASPX WebShell£¬£¬£¬×îÖÕʵÏÖÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬¿ÉÄܵ¼ÖÂÃô¸ÐÊý¾Ýй¶¡¢ÏµÍ³ÍêȫʧÏݼ°ºáÏòÉøÍ¸µÈÑÏÖØÇ徲Σº¦¡£¡£¡£


¶þ¡¢Ó°Ïì¹æÄ£


Storage Zone Controller 5.x <= 5.12.3


Èý¡¢Çå¾²²½·¥


3.1 Éý¼¶°æ±¾


¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£
Storage Zone Controller >= 5.12.4


ÏÂÔØÁ´½Ó£ºhttps://docs.sharefile.com/en-us/storage-zones-controller/5-0/upgrade/


3.2 ÔÝʱ²½·¥


ÔÝÎÞ¡£¡£¡£


3.3 ͨÓý¨Òé


? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬ïÔ̭ϵͳÎó²î£¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£
ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£
ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£
ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£
ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://www.cve.org/CVERecord?id=CVE-2026-2701/
https://www.cve.org/CVERecord?id=CVE-2026-2699
https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/
https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26