CVE-2026-0971
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2026-0971 is an improper session timeout vulnerability (CWE-613: Insufficient Session Expiration) in Fortra's GoAnywhere Managed File Transfer (MFT) product. The flaw causes SAML-configured Web Users to be redirected to the standard login page instead of the SAML login page upon session timeout, potentially exposing credentials to interception. All versions of GoAnywhere MFT prior to 7.10.0 are affected. The vulnerability was published on April 21, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium), assigned by Fortra (GitHub Advisory, Fortra Advisory).

Technical details

The root cause is classified as CWE-613 (Insufficient Session Expiration), where the application fails to properly handle session expiration for SAML-authenticated users. When a SAML-configured Web User's session times out, the application incorrectly redirects the user to the standard username/password login page rather than the organization's SAML Identity Provider (IdP) login page. This breaks the expected SAML authentication flow and could expose users to credential harvesting if an attacker has positioned themselves to intercept or spoof the login page. The attack vector is network-based, requires no privileges, but does require user interaction (the user must experience a session timeout) (GitHub Advisory, Fortra Advisory).

Impact

The primary impact is a low confidentiality risk: SAML-configured users redirected to the regular login page may inadvertently submit credentials through a non-SAML authentication path, creating an opportunity for credential harvesting or phishing. There is no integrity or availability impact associated with this vulnerability. The scope is limited to the affected GoAnywhere MFT instance, with no evidence of lateral movement potential directly attributable to this flaw (GitHub Advisory).

Mitigation and workarounds

Fortra has addressed this vulnerability in GoAnywhere MFT version 7.10.0. Organizations running any version prior to 7.10.0 should upgrade immediately. As an interim measure for organizations unable to patch right away, Fortra recommends monitoring SAML authentication flows and session management for anomalous redirect behavior, and restricting access to the GoAnywhere MFT web interface to trusted networks. Enforcing multi-factor authentication where possible can also reduce the risk of credential exposure (Fortra Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management