PT-2026-36613 · Unknown+1 · Crushftp Enterprise Managed File Transfer+1
CVE-2026-40400
·
Published
2026-05-02
·
Updated
2026-07-22
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CrushFTP Enterprise Managed File Transfer versions prior to 11.1.0
Description
An unauthenticated remote code execution flaw exists due to a Server-Side Template Injection (SSTI) in the web-based management interface. SSTI is a vulnerability where an application improperly sanitizes user input used in a template engine, allowing the execution of arbitrary code. The issue occurs when the server treats certain user-controlled URL parameters as executable template expressions, enabling an attacker to reference Java-level system objects such as
java.lang.Runtime to execute system commands. This allows the attacker to bypass the Virtual File System (VFS) sandbox—a security mechanism intended to restrict users to specific directories—and gain the ability to read, modify, or delete any file on the host operating system. Approximately 2,700 exposed instances worldwide are potentially affected, including critical government, banking, and healthcare assets. Real-world exploitation has been observed involving the use of automated exploit kits to exfiltrate database credentials and internal API keys.Recommendations
Update CrushFTP Enterprise Managed File Transfer to version 11.1.0 or 10.7.1 or higher.
Restrict access to the web management interface to trusted IP ranges only.
Disable web-based management over the public internet and use a VPN or local console access.
Fix
RCE
DoS
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crushftp Enterprise Managed File Transfer
Windows