Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223853 vulns · 37/41 feeds (7d)
← Back to list
7.2
CVE-2026-16139PATCHED
progress · sharefile storage zones controller

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

Description

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

Affected Products

VendorProductVersions
progresssharefile storage zones controller0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
citrixsharefile storagezonescert_advisory90%

References

  • https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories40d ago
[NEU] [hoch] Citrix Systems ShareFile StorageZones Controller: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB41d ago
CVE-2026-16139 | Progress ShareFile Storage Zones Controller up to 5.12.5/6.0.2 path traversal
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.2 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-SZC-Service-Disruption-Guidance-Login-Issues-and-Access-Information
CWECWE-22, CWE-73, CWE-20
PublishedAug 17, 2026
Last enriched41d ago
Trending Score1
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-80462
Privilege Escalation in Progress Chef Automate
Trending: 7
HIGHCVE-2026-13184
RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 6
HIGHCVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 6
HIGHCVE-2026-18672
RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 3
HIGHCVE-2026-19219
DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 3

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 18, 2026