CVE-2026-15913 PUBLISHED

Path Traversal in Fortra's GoAnywhere MFT Endpoint

Assigner: Fortra
Reserved: 15.07.2026 Published: 09.09.2026 Updated: 09.09.2026

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 7.7

Product Status

Vendor Fortra
Product GoAnywhere MFT
Versions Default: unaffected
  • affected from 0 to 7.10.2 (excl.)

Solutions

Upgrade to a remediated version (version 7.10.2 or later).

Credits

  • xtromera (Zerosploit) https://www.zerosploit.co/ reporter
  • ZeyadZonkorany (Zerosploit) https://www.zerosploit.co/ reporter
  • 0xkalawy (Zerosploit) https://www.zerosploit.co/ reporter

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-126 Path Traversal