CVE-2026-16139 - Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
CVE ID :CVE-2026-16139
Published : Aug. 17, 2026, 2:20 p.m. | 1 hour, 10 minutes ago
Description :In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 17, 2026, 2:20 p.m. | 1 hour, 10 minutes ago
Description :In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...