CVE-2026-16138: Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress ShareFile Storage Zones Controllerto a version that resolves this vulnerability.Fixed in 5.12.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16138?
The severity of CVE-2026-16138 is rated high with a CVSS score of 8.
How does CVE-2026-16138 allow remote code execution?
CVE-2026-16138 allows remote code execution through unsafe deserialization of untrusted file metadata by users with write access.
Which versions of Progress ShareFile Storage Zones Controller are affected by CVE-2026-16138?
Progress ShareFile Storage Zones Controller versions 5.12.5 and below are affected by CVE-2026-16138.
What are the potential impacts of CVE-2026-16138?
The potential impacts of CVE-2026-16138 include arbitrary code execution on the Storage Zones Controller host.
How do I mitigate CVE-2026-16138?
To mitigate CVE-2026-16138, upgrade to a version of the Progress ShareFile Storage Zones Controller that is above 5.12.5.