CVE-2025-8148
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-05

Last updated on: 2025-12-08

Assigner: Fortra

Description
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-05
Last Modified
2025-12-08
Generated
2026-06-16
AI Q&A
2025-12-05
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
fortra goanywhere_mft *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is an Improper Access Control issue in the SFTP service of Fortra's GoAnywhere MFT before version 7.9.0. It allows Web Users who have an Authentication Alias and a valid SSH key, but are supposed to be limited to Password authentication for SFTP, to bypass this restriction and still log in using their SSH key.

Impact Analysis

The vulnerability could allow unauthorized access to the SFTP service by users who should be restricted to password authentication only, potentially leading to unauthorized data access or modification. This could compromise confidentiality and integrity of data transferred via SFTP.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-8148. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart