PatchSiren

StoneFly CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL StoneFly CVE published 2026-06-30

CVE-2026-56415

The StoneFly Storage Concentrator contains a command injection vulnerability within the debug.pl script, allowing remote attackers to execute arbitrary commands with root-level privileges. The vulnerability is reachable without authentication and has a CVSS score of 10. Affected product context indicates that industrial control system administrators and cybersecurity teams responsible for ICS security sho [truncated]

CRITICAL StoneFly CVE published 2026-06-30

CVE-2026-55721

The StoneFly Storage Concentrator is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts, allowing an unauthenticated remote attacker to manipulate database queries and extract sensitive information. This vulnerability has a CVSS score of 9.3 and is considered critical. Organizations using StoneFly Storage Concentrator should prioritize upgrading to version 8.0 [truncated]

CRITICAL StoneFly CVE published 2026-06-30

CVE-2026-50110

StoneFly Storage Concentrator contains hardcoded credentials for numerous internal services embedded within a configuration file. The credentials are stored in an encoded format that can be reversed to plaintext, potentially allowing unauthorized access to multiple interconnected systems, including database accounts, licensing, replication services, and third-party integrations. Successful exploitation co [truncated]

MEDIUM StoneFly CVE published 2026-06-30

CVE-2026-50040

The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie th [truncated]