CVE-2026-16137 PUBLISHED

Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller

Assigner: ProgressSoftware
Reserved: 17.07.2026 Published: 17.08.2026 Updated: 18.08.2026

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Progress
Product ShareFile Storage Zones Controller
Versions Default: unaffected
  • affected from 0 to 5.12.5 (incl.)

Solutions

Upgrade to ShareFile Storage Zones Controller v5.12.6 or later.

Credits

  • Piotr Bazydlo (@chudyPB) of watchTowr finder

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE
  • CWE-73: External Control of File Name or Path CWE
  • CWE-434: Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • Upload of malicious file using path traversal leading to remote code execution.