PT-2026-76651 · Unknown · Sharefile Storagezones Controller

CVE-2026-16137

·

Published

2026-08-17

·

Updated

2026-09-02

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions In Progress ShareFile Storage Zones Controller versions prior to 5.12.6
Description A party with valid zone credentials can perform path traversal via the resumable upload initiation endpoint. This allows the party to write arbitrary content to any location writable by the application's service account, which may lead to the execution of attacker-supplied code. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations Update In Progress ShareFile Storage Zones Controller to version 5.12.6 or later.

Fix

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16137

Affected Products

Sharefile Storagezones Controller