CVE-2026-16138 PUBLISHED

Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service

Assigner: ProgressSoftware
Reserved: 17.07.2026 Published: 17.08.2026 Updated: 18.08.2026

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8

Product Status

Vendor Progress
Product ShareFile Storage Zones Controller
Versions Default: unaffected
  • affected from 0 to 5.12.5 (incl.)

Solutions

Upgrade to ShareFile Storage Zones Controller version 5.12.6 or later.

References

Problem Types

  • CWE-502: Deserialization of Untrusted Data CWE

Impacts

  • A user with write access to a Network share can achieve arbitrary code execution with the privileges of the service account.