Executive brief
StoneFly Storage Concentrator, a solution used for managing enterprise data storage and virtualization, contains a critical security flaw. An unauthenticated attacker can remotely execute commands with the highest level of system privileges (root) by sending a specially crafted web request. This could lead to a total system takeover, theft of sensitive data, or complete disruption of storage operations.
Technical details
A command injection vulnerability (CWE-78) exists in the StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) within the 'debug.pl' script. The flaw stems from improper neutralization of special elements in HTTP requests, allowing the input to be executed as OS commands. An unauthenticated remote attacker can exploit this by sending a specially crafted HTTP request to the vulnerable script. Successful exploitation results in arbitrary command execution with root privileges. StoneFly recommends upgrading to version 8.0.4.29 or later to remediate this issue.
Affected products
- StoneFly Storage Concentrator (SC) < 8.0.4.22
- StoneFly Storage Concentrator Virtual Machine (SCVM) < 8.0.4.22
Timeline
- 2026-06-30: advisory: CISA ICSA-26-181-06 published
- 2026-06-30: disclosed: CVE-2026-56415 published to NVD