CVE-2025-1241
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2025-1241 is a cryptographic weakness in Fortra's GoAnywhere Managed File Transfer (MFT) and GoAnywhere Agents that allows admin users to brute-force decrypt sensitive encrypted data due to the use of a static Initialization Vector (IV). The vulnerability affects GoAnywhere MFT versions prior to 7.10.0 and GoAnywhere Agents versions prior to 2.2.0, running on Windows, Linux, and macOS platforms. It was disclosed on April 21, 2026, with NVD initial analysis completed on April 23, 2026. The CVSS v3.1 base score is 4.9 (Medium) per NIST/NVD, and 5.8 (Medium) per Fortra as the CNA (Github Advisory, Fortra Advisory).

Technical details

The root cause is classified as CWE-326 (Inadequate Encryption Strength): the affected products use a static IV in their encryption scheme, which undermines the security of the cipher by making encrypted outputs deterministic and predictable for identical plaintext inputs. A static IV in block cipher modes (such as CBC or CTR) eliminates the randomness that prevents pattern analysis and brute-force attacks against ciphertext. An attacker with admin-level access to the system can leverage this weakness to systematically brute-force the decryption of stored or transmitted encrypted values. No public proof-of-concept exploit code has been identified at this time (Github Advisory, Fortra Advisory).

Impact

Successful exploitation results in a high confidentiality impact, as an admin-level attacker can brute-force decrypt sensitive data protected by the flawed encryption scheme — potentially exposing credentials, file transfer configurations, or other sensitive information stored within GoAnywhere MFT or its agents. There is no integrity or availability impact associated with this vulnerability. The scope of impact is limited to the affected component under NIST's scoring, though Fortra's own scoring indicates a potential scope change, suggesting encrypted data from one component could be exposed in another context (Fortra Advisory, Github Advisory).

Exploitation steps

  1. Gain Admin Access: Obtain administrative credentials or session access to a vulnerable GoAnywhere MFT instance (prior to version 7.10.0) or GoAnywhere Agent (prior to version 2.2.0) through legitimate means, credential theft, or prior compromise.
  2. Extract Encrypted Values: As an admin user, access stored encrypted values within the GoAnywhere MFT configuration, database, or agent settings — such as encrypted passwords, API keys, or connection credentials.
  3. Identify Static IV: Analyze the extracted ciphertext to confirm the use of a static IV, which can be identified by observing that identical plaintext inputs produce identical ciphertext outputs.
  4. Brute-Force Decryption: Leverage the static IV to mount a brute-force or known-plaintext attack against the encrypted data, systematically testing decryption keys until the plaintext is recovered.
  5. Leverage Decrypted Data: Use the recovered plaintext (e.g., credentials, connection strings) to access downstream systems, escalate privileges, or facilitate lateral movement within the environment (Fortra Advisory, Github Advisory).

Mitigation and workarounds

Fortra has released patched versions addressing this vulnerability: GoAnywhere MFT version 7.10.0 and GoAnywhere Agents version 2.2.0. Organizations should upgrade to these versions or later as the primary remediation. No specific configuration-based workarounds have been publicly documented; restricting admin account access and enforcing strong authentication controls can reduce the risk of exploitation in the interim (Fortra Advisory, Github Advisory).

Community reactions

The vulnerability received routine coverage from vulnerability tracking platforms and security aggregators, including CISA's weekly vulnerability bulletin for the week of April 20, 2026. No notable independent researcher commentary, vendor statements beyond the official advisory, or significant social media discussion has been identified. Community reaction appears muted, consistent with the moderate severity rating and the requirement for admin-level privileges to exploit (CISA Bulletin, RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management