Critical severity9.8NVD Advisory· Published Apr 24, 2026· Updated Apr 24, 2026
CVE-2026-39920
CVE-2026-39920
Description
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: < 24A (released early 2024)
Patches
Vulnerability mechanics
References
5- axis.apache.org/axis2/java/core/docs/webadminguide.htmlnvd
- gist.github.com/VAMorales/9e6a13d7529c079a363930dff48be3banvd
- issues.apache.org/jira/browse/AXIS2-4279nvd
- www.bridgeheadsoftware.com/rapid-data-protection-product-updates/nvd
- www.vulncheck.com/advisories/bridgehead-filestore-24a-apache-axis2-default-credentials-rcenvd
News mentions
0No linked articles in our index yet.