CVE-2026-16139: Remote Code Execution Risk in ShareFile Storage Zones Controller
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-16139 affects Progress ShareFile Storage Zones Controller versions 5.12.5 and earlier, and 6.0.2 and earlier. An authenticated zone administrator can exploit improper validation in the download preparation flow, allowing attacker-controlled files to be written outside the intended directory. This vulnerability can lead to remote code execution in v5 versions, although exploitation on v6 versions is unconfirmed. The CVSS score for this vulnerability is 7.2, indicating a high severity level. No public proof-of-concept or confirmed exploitation has been reported as of now. Users are advised to upgrade to versions newer than 5.12.5 for v5 and 6.0.2 for v6, and to restrict zone administrator privileges. Monitoring file system activity for unexpected writes is also recommended.
Key Points: • CVE-2026-16139 allows remote code execution in affected ShareFile versions. • No confirmed exploitation or public proof-of-concept exists yet. • Users should upgrade to the latest versions and monitor file system activity.