← Browse

CVE-2026-15724

Medium

Elevated severity or exploit probability.

CVSS base
8.7 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
EPSS — probability of exploitation (30 days)
0.5%
43.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-20
Published 2026-07-21 · modified 2026-09-03

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredHHigh
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityHHigh
AvailabilityNNone

Timeline

Description

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.

Affected

progress

References

Official: NVD · CVE.org