Description
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to ShareFile Storage Zones Controller v5.12.6 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 17 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code. | |
| Title | Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller | |
| Weaknesses | CWE-22 CWE-434 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-17T15:37:30.951Z
Reserved: 2026-07-17T16:56:49.395Z
Link: CVE-2026-16137
No data.
Status : Received
Published: 2026-08-17T14:20:19.670
Modified: 2026-08-17T14:20:19.670
Link: CVE-2026-16137
No data.
OpenCVE Enrichment
No data.