PT-2026-76653 · In Progress · Sharefile Storagezones Controller

CVE-2026-16139

·

Published

2026-08-17

·

Updated

2026-09-02

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions In Progress ShareFile Storage Zones Controller versions prior to 5.12.6 In Progress ShareFile Storage Zones Controller versions prior to 6.0.3
Description An authenticated zone administrator can exploit improper validation within the download preparation flow. This flaw allows files controlled by an attacker to be written outside the intended preparation directory, which may lead to remote code execution in v5 versions. Remote code execution has not been confirmed for v6 versions.
Recommendations Update In Progress ShareFile Storage Zones Controller to a version later than 5.12.5. Update In Progress ShareFile Storage Zones Controller to a version later than 6.0.2.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16139

Affected Products

Sharefile Storagezones Controller