PT-2026-36613 · Unknown+1 · Crushftp Enterprise Managed File Transfer+1

CVE-2026-40400

·

Published

2026-05-02

·

Updated

2026-07-22

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CrushFTP Enterprise Managed File Transfer versions prior to 11.1.0
Description An unauthenticated remote code execution flaw exists due to a Server-Side Template Injection (SSTI) in the web-based management interface. SSTI is a vulnerability where an application improperly sanitizes user input used in a template engine, allowing the execution of arbitrary code. The issue occurs when the server treats certain user-controlled URL parameters as executable template expressions, enabling an attacker to reference Java-level system objects such as java.lang.Runtime to execute system commands. This allows the attacker to bypass the Virtual File System (VFS) sandbox—a security mechanism intended to restrict users to specific directories—and gain the ability to read, modify, or delete any file on the host operating system. Approximately 2,700 exposed instances worldwide are potentially affected, including critical government, banking, and healthcare assets. Real-world exploitation has been observed involving the use of automated exploit kits to exfiltrate database credentials and internal API keys.
Recommendations Update CrushFTP Enterprise Managed File Transfer to version 11.1.0 or 10.7.1 or higher. Restrict access to the web management interface to trusted IP ranges only. Disable web-based management over the public internet and use a VPN or local console access.

Fix

RCE

DoS

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40400
ZDI-26-414

Affected Products

Crushftp Enterprise Managed File Transfer
Windows