CVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
Configurations

No configuration.

History

21 Jul 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 17:17

Updated : 2026-07-24 05:16


NVD link : CVE-2026-15724

Mitre link : CVE-2026-15724

CVE.ORG link : CVE-2026-15724


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path