In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
Upgrade to ShareFile Storage Zones Controller version 5.12.6 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress sharefile Storage Zones Controller |
|
| Vendors & Products |
Progress
Progress sharefile Storage Zones Controller |
Mon, 17 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |
| Title | Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-08-17T15:37:44.077Z
Reserved: 2026-07-17T16:56:50.099Z
Link: CVE-2026-16138
No data.
Status : Received
Published: 2026-08-17T14:20:19.797
Modified: 2026-08-17T16:16:51.137
Link: CVE-2026-16138
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:45:03Z
Weaknesses