File Disclosure Vulnerability in SFTPGo Affected by Path Validation Flaw
CVE-2026-49244
5.9MEDIUM
What is CVE-2026-49244?
SFTPGo, an event-driven file transfer solution, has a vulnerability affecting its public web-client that allows an unauthenticated requester to exploit path validation flaws. Specifically, the partial ZIP download endpoint fails to correctly validate file entries, enabling access to files outside the designated share directory when certain path prefixes are used. This could lead to unintended disclosure of directory contents by allowing files outside the intended scope to be included in the generated downloads. This issue was addressed in version 2.7.3.
Affected Version(s)
sftpgo >= 2.2.0 < 2.7.2
