云虫漏洞库

CVE-2026-16139 - In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions. - 漏洞详情

漏洞编号:CVE-2026-16139

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-16139

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-20

发布/更新时间:2026-08-17 / 2026-08-28

漏洞描述

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.

相关链接

相关漏洞

« 返回首页