Path Traversal Vulnerability in Fortra's GoAnywhere MFT
CVE-2026-15913
7.7HIGH
What is CVE-2026-15913?
A path traversal vulnerability exists in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT. This issue affects users with both Secure Folders and Secure Mail permissions, allowing them to escape their sandboxed home directories. Consequently, this allows unauthorized access to arbitrary files within the system, potentially compromising sensitive information. Users are advised to update to version 7.10.2 or later to mitigate this risk.
Affected Version(s)
GoAnywhere MFT 0 < 7.10.2
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
xtromera (Zerosploit) https://www.zerosploit.co/
ZeyadZonkorany (Zerosploit) https://www.zerosploit.co/
0xkalawy (Zerosploit) https://www.zerosploit.co/