In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to a remediated version (version 7.10.2 or later).
Workaround
No workaround given by the vendor.
References
History
Thu, 10 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortra
Fortra goanywhere Mft |
|
| Vendors & Products |
Fortra
Fortra goanywhere Mft |
Wed, 09 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read. | |
| Title | Path Traversal in Fortra's GoAnywhere MFT Endpoint | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-09-09T21:18:54.261Z
Reserved: 2026-07-15T19:34:18.897Z
Link: CVE-2026-15913
No data.
Status : Received
Published: 2026-09-09T22:17:11.367
Modified: 2026-09-09T22:17:11.367
Link: CVE-2026-15913
No data.
OpenCVE Enrichment
Updated: 2026-09-10T11:30:06Z
Weaknesses