CVE-2026-15724

Summary

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.

Affected Software

VendorProductVersion RangeStatus
ProgressShareFile Storage Zones Controller0 <= 5.12.4affected
ProgressShareFile Storage Zones Controller6.0.0 <= 6.0.1affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-73: CWE-73: External Control of File Name or Path
  • CWE-20: CWE-20: Improper Input Validation

References