CVE-2026-15724

HIGH

Path traversal in Progress ShareFile Storage Zones Controller (SZC)

Title source: cna
STIX 2.1

Description

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.

Scores

CVSS v3 8.7
EPSS 0.0034
EPSS Percentile 26.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-22 CWE-73
Status published
Products (2)
Progress/ShareFile Storage Zones Controller < 5.12.4
Progress/ShareFile Storage Zones Controller 6.0.0 - 6.0.1
Published Jul 21, 2026
Tracked Since Jul 21, 2026