CVE-2026-16139: Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress ShareFile Storage Zones Controllerto a version that resolves this vulnerability.Fixed in 5.12.6 - Upgrade
Upgrade
Progress ShareFile Storage Zones Controllerto a version that resolves this vulnerability.Fixed in 6.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16139?
CVE-2026-16139 has a severity rating of high with a score of 7.2.
How do I fix CVE-2026-16139?
To fix CVE-2026-16139, upgrade Progress ShareFile Storage Zones Controller to version 5.12.6 or 6.0.3 or later.
What are the potential impacts of exploiting CVE-2026-16139?
Exploitation of CVE-2026-16139 can lead to arbitrary file writes that may enable remote code execution.
Who is affected by CVE-2026-16139?
CVE-2026-16139 affects authenticated zone administrators using Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2.
What type of vulnerability is CVE-2026-16139 categorized as?
CVE-2026-16139 is categorized as a path traversal vulnerability related to improper input validation.