Path traversal in ShareFile storage zones controller - #VU138320

 

Path traversal in ShareFile storage zones controller - #VU138320

Published: July 17, 2026


Vulnerability identifier: #VU138320
CSH Severity: High
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote privileged user can send a specially crafted HTTP request and read arbitrary files on the system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

ShareFile storage zones controller

Remediation

Install updates from vendor's website.

ShareFile storage zones controller - addressed in versions 5.12.5, 6.0.2

External References

Related Security Bulletins