CVE-2025-14362
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2025-14362 is a brute force vulnerability in the SFTP service of Fortra's GoAnywhere Managed File Transfer (MFT) platform. The flaw allows unauthenticated remote attackers to perform unlimited SSH key guessing attempts against Web User accounts configured for SSH Key authentication, as no login rate limiting or account lockout is enforced in this scenario. All versions of GoAnywhere MFT prior to 7.10.0 are affected. The CVE was published on April 21, 2026, with NVD initial analysis completed on April 23, 2026. It carries a CVSS v3.1 base score of 7.3 (High), assigned by Fortra (GitHub Advisory, Fortra Advisory).

Technical details

The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). Specifically, GoAnywhere MFT's SFTP service fails to apply its configured login attempt limits when a Web User account is set to authenticate via SSH Key rather than a password, creating a gap in the authentication rate-limiting logic. An unauthenticated attacker on the network can exploit this by repeatedly attempting SSH connections with different key material against a target account, with no lockout or throttling applied. No special privileges or user interaction are required, and the attack vector is entirely network-based (GitHub Advisory, Fortra Advisory).

Impact

Successful exploitation could allow an attacker to gain unauthorized access to the GoAnywhere MFT SFTP service, enabling them to read, modify, or delete sensitive files managed by the platform. The impact spans confidentiality, integrity, and availability — all rated Low in the CVSS scoring — reflecting that access is scoped to the SFTP service rather than the full underlying system. However, given that GoAnywhere MFT is commonly used to transfer sensitive business and regulated data, unauthorized SFTP access could expose critical files and enable further lateral movement within connected systems (GitHub Advisory, Fortra Advisory).

Exploitation steps

  1. Reconnaissance: Use internet scanning tools such as Shodan or Censys to identify internet-facing GoAnywhere MFT instances with SFTP services exposed (typically on port 22 or a custom SFTP port), targeting versions prior to 7.10.0.
  2. Identify target accounts: Enumerate or guess Web User account names configured on the SFTP service. Account names may be discoverable through SFTP banner information, organizational intelligence, or prior data exposure.
  3. Confirm SSH Key authentication: Attempt an SSH connection to determine if the target account uses SSH Key authentication (the server will request a public key rather than a password), confirming the absence of login rate limiting.
  4. Brute force SSH keys: Use automated SSH brute-forcing tools (e.g., custom scripts leveraging Paramiko or similar SSH libraries) to repeatedly attempt authentication with different SSH key pairs, exploiting the lack of lockout or throttling on the SFTP service.
  5. Gain unauthorized access: Upon successfully guessing or matching a valid SSH key, authenticate to the SFTP service and access, exfiltrate, modify, or delete files managed by the GoAnywhere MFT platform (GitHub Advisory, Fortra Advisory).

Indicators of compromise

  • Network: High volume of SSH/SFTP connection attempts from a single or rotating set of external IP addresses to the GoAnywhere MFT SFTP port; repeated failed SSH key authentication attempts in a short time window.
  • Logs: GoAnywhere MFT SFTP access logs showing a large number of failed authentication events for a specific Web User account without corresponding lockout events; absence of account lockout log entries despite repeated failures for SSH Key-authenticated accounts.
  • Process/Service: Unexpected successful SFTP logins from unfamiliar IP addresses or at unusual times, particularly for accounts configured with SSH Key authentication.
  • File System: Unexpected file access, downloads, uploads, or deletions in SFTP-managed directories following anomalous authentication activity.

Mitigation and workarounds

Fortra has addressed this vulnerability in GoAnywhere MFT version 7.10.0; organizations should upgrade to this version or later as the primary remediation (Fortra Advisory). As interim workarounds prior to patching, administrators should implement network-level controls such as IP allowlisting to restrict SFTP access to known, trusted IP ranges, and configure rate limiting or connection throttling at the firewall or load balancer level. Additionally, monitoring SFTP logs for abnormal authentication patterns and enforcing strong SSH key generation practices can reduce exposure risk.

Community reactions

The vulnerability was noted in the CISA weekly vulnerability bulletin for the week of April 20, 2026, and covered by security aggregators including Red Packet Security and EGFinCIRT (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability database aggregation.

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management