
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14362 is a brute force vulnerability in the SFTP service of Fortra's GoAnywhere Managed File Transfer (MFT) platform. The flaw allows unauthenticated remote attackers to perform unlimited SSH key guessing attempts against Web User accounts configured for SSH Key authentication, as no login rate limiting or account lockout is enforced in this scenario. All versions of GoAnywhere MFT prior to 7.10.0 are affected. The CVE was published on April 21, 2026, with NVD initial analysis completed on April 23, 2026. It carries a CVSS v3.1 base score of 7.3 (High), assigned by Fortra (GitHub Advisory, Fortra Advisory).
The root cause is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). Specifically, GoAnywhere MFT's SFTP service fails to apply its configured login attempt limits when a Web User account is set to authenticate via SSH Key rather than a password, creating a gap in the authentication rate-limiting logic. An unauthenticated attacker on the network can exploit this by repeatedly attempting SSH connections with different key material against a target account, with no lockout or throttling applied. No special privileges or user interaction are required, and the attack vector is entirely network-based (GitHub Advisory, Fortra Advisory).
Successful exploitation could allow an attacker to gain unauthorized access to the GoAnywhere MFT SFTP service, enabling them to read, modify, or delete sensitive files managed by the platform. The impact spans confidentiality, integrity, and availability — all rated Low in the CVSS scoring — reflecting that access is scoped to the SFTP service rather than the full underlying system. However, given that GoAnywhere MFT is commonly used to transfer sensitive business and regulated data, unauthorized SFTP access could expose critical files and enable further lateral movement within connected systems (GitHub Advisory, Fortra Advisory).
Fortra has addressed this vulnerability in GoAnywhere MFT version 7.10.0; organizations should upgrade to this version or later as the primary remediation (Fortra Advisory). As interim workarounds prior to patching, administrators should implement network-level controls such as IP allowlisting to restrict SFTP access to known, trusted IP ranges, and configure rate limiting or connection throttling at the firewall or load balancer level. Additionally, monitoring SFTP logs for abnormal authentication patterns and enforcing strong SSH key generation practices can reduce exposure risk.
The vulnerability was noted in the CISA weekly vulnerability bulletin for the week of April 20, 2026, and covered by security aggregators including Red Packet Security and EGFinCIRT (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."