In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to ShareFile Storage Zones Controller version 5.12.5 or 6.0.2 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Title | Path traversal in Progress ShareFile Storage Zones Controller (SZC) | |
| Weaknesses | CWE-20 CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-07-21T16:55:34.486Z
Reserved: 2026-07-14T13:13:06.485Z
Link: CVE-2026-15724
No data.
No data.
No data.
OpenCVE Enrichment
No data.