High severity7.2NVD Advisory· Published Aug 17, 2026
CVE-2026-16137
CVE-2026-16137
Description
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
Affected products
1- Range: <=5.12.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.