


Perceptive Security
SOC/SIEM Consultancy

BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default c…
Published:
23 April 2026 at 22:00:00
Alert date:
24 April 2026 at 17:03:09
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
BridgeHead FileStore versions prior to 24A expose the Apache Axis2 administration module with default credentials on network-accessible endpoints. Unauthenticated remote attackers can exploit this vulnerability to execute arbitrary OS commands. The attack involves authenticating to the admin console using default credentials, uploading a malicious Java archive as a web service, and executing commands via SOAP requests to the deployed service. This vulnerability affects versions released before early 2024 and represents a critical security flaw allowing complete system compromise.
Technical details
Mitigation steps:
Affected products:
BridgeHead FileStore
Apache Axis2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-39920
https://axis.apache.org/axis2/java/core/docs/webadminguide.html
https://gist.github.com/VAMorales/9e6a13d7529c079a363930dff48be3ba
https://issues.apache.org/jira/browse/AXIS2-4279
https://www.bridgeheadsoftware.com/rapid-data-protection-product-updates/
https://www.vulncheck.com/advisories/bridgehead-filestore-24a-apache-axis2-default-credentials-rce
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
