HIGH🇵🇱 Wersja polska

CVE-2026-16137

CVSS 7.2v3.1pub. 2026-08-17upd. 2026-09-02

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Progress Sharefile Storage Zones Controller

    APP
    Progress
    ≤ 5.12.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-2699CRITICAL9.8PL ✓same product

Auth Bypass i RCE w Progress ShareFile Storage Zones Controller

CVE-2026-2701CRITICAL9.1PL ✓same product

RCE w Progress Sharefile Storage Zones Controller — upload złośliwego pliku

CVE-2026-16138HIGH8.0same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted...

CVE-2026-16139HIGH7.2same product

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administ...

CVE-2026-15724HIGH8.7PL ✓same product

Path traversal w Progress ShareFile Storage Zones Controller