CVE-2025-8148
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2025-8148 is an Improper Access Control vulnerability in the SFTP service of Fortra's GoAnywhere Managed File Transfer (MFT) product. It allows Web Users who have an Authentication Alias and a valid SSH key — but whose accounts are explicitly restricted to Password authentication for SFTP — to bypass that restriction and authenticate using their SSH key instead. All versions of GoAnywhere MFT prior to 7.9.0 are affected. The vulnerability was published on December 5, 2025, and assigned a CVSS v3.1 base score of 4.2 (Medium) by Fortra (Fortra Advisory, NVD).

Technical details

The root cause is classified under CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-863 (Incorrect Authorization), indicating that the SFTP service fails to properly enforce the configured authentication method restriction for Web Users using Authentication Aliases (NVD). Specifically, when a Web User account is configured with an Authentication Alias and is restricted to Password-only SFTP authentication, the service does not correctly validate this constraint, allowing a valid SSH key to be accepted as an alternative credential. Exploitation requires network access, low-level privileges (a valid account with an SSH key), and high attack complexity, with no user interaction needed (Fortra Advisory).

Impact

Successful exploitation allows an attacker to authenticate to the SFTP service using an SSH key on an account that should be restricted to password-only authentication, bypassing an intended security control. The confidentiality and integrity impacts are both rated Low, meaning an attacker could gain unauthorized read/write access to files within the scope of the compromised Web User account. Availability is not impacted, and the vulnerability scope is unchanged, limiting blast radius to the permissions of the affected user account (NVD, Fortra Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2025-8148. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.044%, indicating a very low probability of exploitation in the near term (NVD). No threat actor attribution has been identified at this time.

Exploitation steps

  1. Reconnaissance: Identify internet-facing GoAnywhere MFT instances running versions prior to 7.9.0 using tools such as Shodan or Censys, targeting exposed SFTP ports (typically TCP 22 or a custom port).
  2. Identify target account: Obtain or possess credentials for a Web User account that has an Authentication Alias configured and a valid SSH key pair, but is administratively restricted to Password-only SFTP authentication.
  3. Attempt SSH key authentication: Connect to the GoAnywhere MFT SFTP service using an SSH client (e.g., sftp -i <private_key> user@target) with the SSH private key corresponding to the account's registered public key.
  4. Bypass authentication restriction: Due to the improper access control flaw, the SFTP service accepts the SSH key authentication despite the Password-only restriction, granting the attacker an authenticated SFTP session.
  5. Access files: Use the authenticated SFTP session to read or write files within the scope of the Web User's permissions, potentially accessing sensitive transferred data (Fortra Advisory, NVD).

Indicators of compromise

  • Logs: GoAnywhere MFT audit logs showing SFTP authentication events using SSH key (publickey) method for Web User accounts that are configured with Password-only authentication restrictions; unexpected successful SFTP logins for accounts expected to use only password authentication.
  • Network: SFTP connections (TCP port 22 or configured SFTP port) from unexpected source IPs for accounts with Authentication Aliases; SSH key-based handshakes from clients not previously observed for restricted accounts.
  • Application: GoAnywhere MFT event logs recording SSH public key authentication successes for Web Users whose authentication method is set to Password only.

Mitigation and workarounds

Fortra has released GoAnywhere MFT version 7.9.0, which resolves this vulnerability. Organizations should upgrade to version 7.9.0 or later as the primary remediation (Fortra Advisory). As an interim workaround, administrators can review and remove SSH public keys from Web User accounts that are restricted to Password-only SFTP authentication, or temporarily disable SFTP access for affected accounts until patching is complete. Additionally, restricting SFTP access to known IP ranges via network controls can reduce exposure.

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management