← back
CVE-2026-16139highCWE-20CWE-22CWE-73

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.7%
exploitation probability
0.7%top 51% of all CVEs
observed exploitation
nono source reports it
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H