Junglewise Threat Intelligence

CVE-2026-15913: Fortra GoAnywhere MFT path traversal in attachRemoteFiles endpoint

CVE-2026-15913 · Severity: high · CVSS 7.7 · Published 2026-09-09

Technologies: Fortra GoAnywhere MFT. Vendors: Fortra.

Executive brief

GoAnywhere MFT is a managed file transfer solution used by organizations to securely exchange files. A path traversal vulnerability in the file attachment feature allows authenticated users with specific permissions to read arbitrary files outside their intended sandbox directory, potentially exposing sensitive business data and system files.

Technical details

The vulnerability is a path traversal flaw in the /attachRemoteFiles endpoint of GoAnywhere MFT versions prior to 7.10.2. An attacker with valid Web User credentials and both Secure Folders and Secure Mail permissions can manipulate file path parameters to escape the sandboxed home directory and access arbitrary files on the system. This requires authentication and specific permission grants, but no additional user interaction. The attack leads to unauthorized information disclosure. The vendor has released version 7.10.2 and later as a fix.

Affected products

  • Fortra GoAnywhere MFT prior to 7.10.2

Timeline

  • 2026-09-09: disclosed
  • 2026-09-09: patched: Fixed in version 7.10.2 and later

References

Related threats