Junglewise Threat Intelligence

CVE-2026-15724: Progress ShareFile Storage Zones Controller path traversal

CVE-2026-15724 · Severity: high · CVSS 8.7 · Published 2026-07-21

Vendors: Progress Software Corporation.

Executive brief

Progress ShareFile Storage Zones Controller, a tool used by organizations to manage and store data in private or cloud-based storage, is affected by a security flaw. An authorized administrator could exploit this vulnerability to bypass security restrictions and access or modify sensitive files on the server. This could lead to the theft of confidential data or the unauthorized alteration of system files, potentially compromising the integrity of the storage environment.

Technical details

A path traversal vulnerability exists in Progress ShareFile Storage Zones Controller due to improper input validation (CWE-20, CWE-22, CWE-73). An attacker with administrative privileges can leverage this flaw via network requests to escape the intended directory structure. This allows for arbitrary file read and write operations on the underlying server filesystem. Successful exploitation could lead to full system compromise or data exfiltration. The issue is resolved in versions 5.12.5 and 6.0.2.

Affected products

  • Progress Software Corporation ShareFile Storage Zones Controller Prior to 5.12.5 and 6.0.2

Timeline

  • 2026-07-21: advisory: Initial disclosure by Progress Software Corporation and NVD publication.
  • 2026-07-21: disclosed

References