Unauthenticated File Access in goshs Server Software by goshs Labs
CVE-2026-62325

9.1CRITICAL

Key Information:

Vendor

Goshs-labs

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-62325?

The goshs Server Software is affected by an issue where the SFTP authentication mechanism fails to properly enforce security policies, allowing unauthenticated users to access files. Specifically, the password handler allows access when both Username and Password are not set, which results in the absence of proper authentication. Users running version 2.1.3 to 2.1.4 with the -b 'admin:' -sftp command, without specifying the -fkf option, will find their systems vulnerable to unauthorized file access. This issue has been addressed in version 2.1.4, urging all users to update immediately to secure their installations.

Affected Version(s)

goshs >= 2.1.3, < 2.1.4

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.