Unsafe Deserialization Vulnerability in ShareFile Storage Zones Controller by Progress
CVE-2026-16138

8HIGH

Key Information:

Vendor

Progress

Vendor
CVE Published:
17 August 2026

What is CVE-2026-16138?

The ShareFile Storage Zones Controller by Progress is susceptible to an unsafe deserialization vulnerability. This flaw involves untrusted file metadata, which can allow an unauthorized user with write access to a network share to execute arbitrary code on the Storage Zones Controller host. This issue affects versions v5.12.5 and earlier, highlighting a significant risk for organizations utilizing this product to manage data securely.

Affected Version(s)

ShareFile Storage Zones Controller 0 <= 5.12.5

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.