CVE-2026-39920

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.
Configurations

No configuration.

History

24 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 16:16

Updated : 2026-06-17 10:42


NVD link : CVE-2026-39920

Mitre link : CVE-2026-39920

CVE.ORG link : CVE-2026-39920


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Insecure Default Initialization of Resource

CWE-1391

Use of Weak Credentials