CVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:sharefile_storage_zones_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:sharefile_storage_zones_controller:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-21 17:17

Updated : 2026-09-03 17:35


NVD link : CVE-2026-15724

Mitre link : CVE-2026-15724

CVE.ORG link : CVE-2026-15724


JSON object : View

Products Affected

progress

  • sharefile_storage_zones_controller
CWE
CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path