Path Traversal in Fortra's GoAnywhere MFT Endpoint

FI-2026-011 - Path Traversal in Fortra's GoAnywhere MFT Endpoint

Severity
High
Published Date
09-Sep-2026
Updated Date
09-Sep-2026
Vulnerabilities
CVE-2026-15913
 
Notes
Description

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

 

Vulnerabilities

 
Path Traversal in Fortra's GoAnywhere MFT Endpoint
Severity
High
CVE
CVE-2026-15913
CWE
CWE-23:Relative path traversal
Discovery Date
08-Jul-2026
CSSv3.1
7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Affected Products
Vulnerability Notes
Remediation: Vendor Fix

Upgrade to a remediated version (version 7.10.2 or later).

 
References