Unauthenticated File Access in goshs Server Software by goshs Labs
CVE-2026-62325
9.1CRITICAL
What is CVE-2026-62325?
The goshs Server Software is affected by an issue where the SFTP authentication mechanism fails to properly enforce security policies, allowing unauthenticated users to access files. Specifically, the password handler allows access when both Username and Password are not set, which results in the absence of proper authentication. Users running version 2.1.3 to 2.1.4 with the -b 'admin:' -sftp command, without specifying the -fkf option, will find their systems vulnerable to unauthorized file access. This issue has been addressed in version 2.1.4, urging all users to update immediately to secure their installations.
Affected Version(s)
goshs >= 2.1.3, < 2.1.4
