What is CVE-2026-16137?
This critical vulnerability (CVE-2026-16137) affects In Progress ShareFile Storage Zones Controller v5.12.5 and below, allowing a party with valid zone credentials to perform path traversal via the resumable upload initiation endpoint and write arbitrary content to any location writable by the service account. Immediate patching and review of zone credentials are strongly recommended.
Azərbaycanca: Bu kritik zəiflik (CVE-2026-16137) In Progress ShareFile Storage Zones Controller-in v5.12.5 və daha aşağı versiyalarına təsir edir və etibarlı zona etimadnaməsinə malik şəxsə "path traversal" həyata keçirərək xidmət hesabının yaza bildiyi hər hansı bir yerə "arbitrary content" yazmağa imkan verir. Təsirə məruz qalan sistemlərdə dərhal istehsalçı tərəfindən təqdim edilən yeniləmələri tətbiq etmək və zona etimadnamələrini nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What product is affected by CVE-2026-16137?
This critical vulnerability affects In Progress ShareFile Storage Zones Controller versions 5.12.5 and below.
What does an attacker need to exploit CVE-2026-16137?
The attacker needs valid zone credentials to perform path traversal via the resumable upload initiation endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.