ZeroHour

CVE-2026-15913

moderate

Path Traversal Arbitrary File Read in Fortra GoAnywhere MFT

CVSS 3.1
7.7 high
EPSS
<1%p33
Published
()
Modified
AI analysis

A path traversal vulnerability (CWE-23) in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows an authenticated web user to escape the sandbox of their assigned home directory. It is triggered when a Web User granted both the Secure Folders and Secure Mail permissions sends a crafted request to the endpoint with insufficiently constrained paths, traversing outside the sandbox. The attacker gains arbitrary file read on the server with the application's privileges, potentially exposing configuration files, stored credentials, and sensitive transferred data, with no integrity or availability impact. Any GoAnywhere MFT deployment running a version prior to 7.10.2 that has web users holding both permissions is affected. No public proof-of-concept is known, the flaw is not in CISA KEV, and no exploitation has been confirmed to date.

What to do: Upgrade GoAnywhere MFT to 7.10.2 or later. As interim mitigation, review which web users hold both Secure Folders and Secure Mail permissions, restrict or firewall access to /attachRemoteFiles (e.g., at a reverse proxy or WAF), and limit exposure of the GoAnywhere web client to the internet. Check access logs for requests to /attachRemoteFiles from accounts with those permissions to detect potential sandbox escapes.

Affected
Fortra GoAnywhere MFTall versions prior to 7.10.2
Estimated exposure
moderateon the order of a few thousand internet-exposed GoAnywhere MFT deployments, with a broader but unknown installed base — Public internet scans during prior GoAnywhere MFT vulnerability incidents (e.g., the 2023 mass-exploited RCE) showed roughly 1,000-3,000 exposed instances, and this flaw additionally requires web users holding both Secure Folders and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

Weakness
CWE-23
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.