PT-2026-76653 · In Progress · Sharefile Storagezones Controller
CVE-2026-16139
·
Published
2026-08-17
·
Updated
2026-09-02
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
In Progress ShareFile Storage Zones Controller versions prior to 5.12.6
In Progress ShareFile Storage Zones Controller versions prior to 6.0.3
Description
An authenticated zone administrator can exploit improper validation within the download preparation flow. This flaw allows files controlled by an attacker to be written outside the intended preparation directory, which may lead to remote code execution in v5 versions. Remote code execution has not been confirmed for v6 versions.
Recommendations
Update In Progress ShareFile Storage Zones Controller to a version later than 5.12.5.
Update In Progress ShareFile Storage Zones Controller to a version later than 6.0.2.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharefile Storagezones Controller