ZeroHour

CVE-2026-16137

CVSS 3.1
7.2 high
EPSS
<1%p42
Published
()
Modified
Description

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

Vendors
progress
Products
sharefile storage zones controller
Weakness
CWE-22, CWE-73, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.