SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16137

HIGH · CVSS 7.2 EPSS 0.52%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

In Progress ShareFile Storage Zones Controller versions up to 5.12.5 are vulnerable to a path traversal attack via the resumable upload initiation endpoint, allowing authenticated users with valid zone credentials to write arbitrary content to any writable location. This could lead to the execution of malicious code, posing a significant risk to the integrity and security of the application. Organizations using this software should prioritize patching to mitigate potential exploitation of this vulnerability.

CVE
CVE-2026-16137
Severity
HIGH
CVSS
7.2
EPSS
0.52%

Original NVD Description

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.

Related CVEs

Other vulnerabilities affecting the same vendor(s)