In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra goanywhere Mft
Vendors & Products Fortra
Fortra goanywhere Mft

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Title Path Traversal in Fortra's GoAnywhere MFT Endpoint
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published: 2026-09-09T21:18:54.261Z

Updated: 2026-09-10T13:49:34.773Z

Reserved: 2026-07-15T19:34:18.897Z

Link: CVE-2026-15913

cve-icon Vulnrichment

Updated: 2026-09-10T13:49:20.827Z

cve-icon NVD

Status : Received

Published: 2026-09-09T22:17:11.367

Modified: 2026-09-10T14:17:00.210

Link: CVE-2026-15913

cve-icon Redhat

No data.