CVE-2026-16137: Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress ShareFile Storage Zones Controllerto a version that resolves this vulnerability.Fixed in 5.12.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16137?
The severity of CVE-2026-16137 is rated as high with a score of 7.2.
How do I fix CVE-2026-16137?
To mitigate CVE-2026-16137, ensure that you upgrade to Progress ShareFile Storage Zones Controller version 5.12.6 or above.
What kind of attack does CVE-2026-16137 involve?
CVE-2026-16137 involves a path traversal vulnerability that allows arbitrary file uploads to writable locations.
Who is impacted by CVE-2026-16137?
Any user with valid zone credentials for Progress ShareFile Storage Zones Controller versions 5.12.5 and below is impacted by CVE-2026-16137.
What can be the potential consequences of CVE-2026-16137?
Exploitation of CVE-2026-16137 may lead to unauthorized file writes to sensitive locations, resulting in data exposure or corruption.