In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra goanywhere Mft |
|
| Vendors & Products |
Fortra
Fortra goanywhere Mft |
Wed, 09 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read. | |
| Title | Path Traversal in Fortra's GoAnywhere MFT Endpoint | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Fortra
Published: 2026-09-09T21:18:54.261Z
Updated: 2026-09-10T13:49:34.773Z
Reserved: 2026-07-15T19:34:18.897Z
Link: CVE-2026-15913
Updated: 2026-09-10T13:49:20.827Z
Status : Received
Published: 2026-09-09T22:17:11.367
Modified: 2026-09-10T14:17:00.210
Link: CVE-2026-15913
No data.