
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0971 is an improper session timeout vulnerability (CWE-613: Insufficient Session Expiration) in Fortra's GoAnywhere Managed File Transfer (MFT) product. The flaw causes SAML-configured Web Users to be redirected to the standard login page instead of the SAML login page upon session timeout, potentially exposing credentials to interception. All versions of GoAnywhere MFT prior to 7.10.0 are affected. The vulnerability was published on April 21, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Fortra (GitHub Advisory, Fortra Advisory).
The root cause is classified as CWE-613 (Insufficient Session Expiration), where the application fails to properly handle session expiration for SAML-authenticated users. When a SAML-configured Web User's session times out, the application incorrectly redirects the user to the standard username/password login page rather than the organization's SAML Identity Provider (IdP) login page. This breaks the expected SAML authentication flow and could expose users to credential harvesting if an attacker has positioned themselves to intercept or spoof the login page. The attack vector is network-based, requires no privileges, but does require user interaction (the user must experience a session timeout) (GitHub Advisory, Fortra Advisory).
The primary impact is a low confidentiality risk: SAML-configured users redirected to the regular login page may inadvertently submit credentials through a non-SAML authentication path, creating an opportunity for credential harvesting or phishing. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the affected GoAnywhere MFT instance, with no evidence of lateral movement potential directly attributable to this flaw (GitHub Advisory).
Fortra has addressed this vulnerability in GoAnywhere MFT version 7.10.0. Organizations running any version prior to 7.10.0 should upgrade immediately. As an interim measure for organizations unable to patch right away, Fortra recommends monitoring SAML authentication flows and session management for anomalous redirect behavior, and restricting access to the GoAnywhere MFT web interface to trusted networks. Enforcing multi-factor authentication where possible can also reduce the risk of credential exposure (Fortra Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."