CVE-2015-2857: Accellion File Transfer Appliance

Critical severity, CVSS 9.8. EPSS: 84.2% chance of exploitation in the next 30 days.

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.

Affected products

  • Accellion File Transfer Appliance: up to and including 9_11_200

Published 2017-08-22. Last modified 2026-06-17.