CVE-2026-16137

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:sharefile_storage_zones_controller:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-17 14:20

Updated : 2026-09-02 18:44


NVD link : CVE-2026-16137

Mitre link : CVE-2026-16137

CVE.ORG link : CVE-2026-16137


JSON object : View

Products Affected

progress

  • sharefile_storage_zones_controller
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path

CWE-434

Unrestricted Upload of File with Dangerous Type