HIGH🇵🇱 Wersja polska

CVE-2026-16139

CVSS 7.2v3.1pub. 2026-08-17upd. 2026-09-02

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Progress Sharefile Storage Zones Controller

    APP
    Progress
    < 5.12.66.0 – 6.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2026-2699CRITICAL9.8PL ✓same product

Auth Bypass i RCE w Progress ShareFile Storage Zones Controller

CVE-2026-2701CRITICAL9.1PL ✓same product

RCE w Progress Sharefile Storage Zones Controller — upload złośliwego pliku

CVE-2026-16137HIGH7.2same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perf...

CVE-2026-16138HIGH8.0same product

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted...

CVE-2026-15724HIGH8.7PL ✓same product

Path traversal w Progress ShareFile Storage Zones Controller