In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
Metrics
Affected Vendors & Products
References
History
Mon, 17 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress sharefile Storage Zones Controller |
|
| Vendors & Products |
Progress
Progress sharefile Storage Zones Controller |
Mon, 17 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code. | |
| Title | Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller | |
| Weaknesses | CWE-22 CWE-434 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-17T15:37:30.951Z
Reserved: 2026-07-17T16:56:49.395Z
Link: CVE-2026-16137
No data.
Status : Received
Published: 2026-08-17T14:20:19.670
Modified: 2026-08-17T16:16:51.040
Link: CVE-2026-16137
No data.
OpenCVE Enrichment
Updated: 2026-08-17T16:00:05Z