CVE-2026-16139 PUBLISHED

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

Assigner: ProgressSoftware
Reserved: 17.07.2026 Published: 17.08.2026 Updated: 18.08.2026

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor Progress
Product ShareFile Storage Zones Controller
Versions Default: unaffected
  • affected from 0 to 5.12.5 (incl.)
  • affected from 6.0.0 to 6.0.2 (incl.)

Solutions

Upgrade to ShareFile Storage Zones Controller versions 5.12.6 or 6.0.3 or later.

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE
  • CWE-73: External Control of File Name or Path CWE
  • CWE-20: Improper Input Validation CWE

Impacts

  • An authenticated zone administrator can write attacker-controlled content to filesystem locations accessible to the Storage Zones Controller service account, potentially executing attacker-controlled code.