Junglewise Threat Intelligence

CVE-2025-8148: An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Ali

CVE-2025-8148 · Severity: medium · CVSS 4.2 · Published 2025-12-05

Vendors: Fortra.

Executive brief

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

Affected products

  • Fortra goanywhere_managed_file_transfer