CVE-2025-14362 PUBLISHED

GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances

Assigner: Fortra
Reserved: 09.12.2025 Published: 21.04.2026 Updated: 21.04.2026

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 7.3

Product Status

Vendor Fortra
Product GoAnywhere MFT
Versions Default: unaffected
  • affected from 0 to 7.10.0 (excl.)

Solutions

Upgrade to patched version.

References

Problem Types

  • CWE-307 Improper restriction of excessive authentication attempts CWE

Impacts

  • CAPEC-49 Password Brute Forcing