File Disclosure Vulnerability in SFTPGo Affected by Path Validation Flaw
CVE-2026-49244

5.9MEDIUM

Key Information:

Vendor

Drakkan

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-49244?

SFTPGo, an event-driven file transfer solution, has a vulnerability affecting its public web-client that allows an unauthenticated requester to exploit path validation flaws. Specifically, the partial ZIP download endpoint fails to correctly validate file entries, enabling access to files outside the designated share directory when certain path prefixes are used. This could lead to unintended disclosure of directory contents by allowing files outside the intended scope to be included in the generated downloads. This issue was addressed in version 2.7.3.

Affected Version(s)

sftpgo >= 2.2.0 < 2.7.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.