CVE-2026-15913
Deferred Deferred - Pending Action

Path Traversal in Fortra GoAnywhere MFT

Vulnerability report for CVE-2026-15913, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: Fortra

Description

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fortra goanywhere_mft to 7.10.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in Fortra's GoAnywhere MFT software versions before 7.10.2. It affects the /attachRemoteFiles endpoint and allows web users with Secure Folders and Secure Mail permissions to escape their restricted home directory. This enables them to read arbitrary files on the system.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized file access attempts via the /attachRemoteFiles endpoint in Fortra's GoAnywhere MFT versions prior to 7.10.2. Monitor server logs for suspicious path traversal patterns, such as requests containing sequences like '../' or '%2e%2e%2f' in file paths. Review access logs for users with Secure Folders and Secure Mail permissions attempting to read files outside their home directories.

Impact Analysis

If exploited, this vulnerability could allow an attacker to access sensitive files outside their restricted directory. This may lead to unauthorized data exposure, including confidential documents or system files. The impact depends on the files accessible and permissions of the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches resulting from this issue.

Mitigation Strategies

Upgrade Fortra GoAnywhere MFT to version 7.10.2 or later to patch the path traversal vulnerability in the /attachRemoteFiles endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15913. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart