CVE-2026-0972
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2026-0972 is an HTML injection vulnerability in system-generated emails in Fortra's GoAnywhere MFT (Managed File Transfer) affecting all versions prior to 7.10.0. The CVE was initially published on April 21, 2026, with an incorrect description (SFTP brute force) that was corrected post-publishing to reflect the actual HTML injection issue (GitHub Advisory, NVD). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) as assigned by Fortra, with a changed scope reflecting potential cross-context impact (NVD).

Technical details

The vulnerability is classified under CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'), specifically manifesting as HTML injection in system-generated emails (NVD). An authenticated attacker with low privileges can inject malicious HTML content into fields that are subsequently included in system-generated email notifications, potentially enabling phishing, content spoofing, or client-side script execution when the email is rendered in a victim's mail client. Exploitation requires user interaction (the recipient opening or viewing the injected email), and the scope is changed, meaning the impact extends beyond the vulnerable GoAnywhere component to the email recipient's environment (GitHub Advisory). A technical write-up was published by SBA Research on April 24, 2026, and a full disclosure post appeared on Seclists (Seclists).

Impact

Successful exploitation allows an attacker to inject arbitrary HTML into system-generated emails sent by GoAnywhere MFT, enabling content spoofing, phishing attacks against email recipients, and potentially executing malicious scripts in vulnerable email clients. The confidentiality and integrity impacts are rated as low, with no availability impact, but the changed scope means the attack can affect users beyond the GoAnywhere system itself — particularly employees or partners who receive automated notifications (NVD, GitHub Advisory). This could facilitate credential harvesting or social engineering campaigns targeting users who trust system-generated communications from the MFT platform.

Exploitation steps

  1. Reconnaissance: Identify a GoAnywhere MFT instance running a version prior to 7.10.0 and obtain low-privileged authenticated access (e.g., a standard user account).
  2. Identify injectable fields: Locate input fields within the GoAnywhere MFT interface that are incorporated into system-generated email notifications (e.g., file transfer notifications, user alerts, or workflow messages).
  3. Craft HTML payload: Prepare a malicious HTML payload such as <a href="https://attacker.com">Click here to verify your account</a> or an image tag pointing to an attacker-controlled server for tracking, or a script tag if the email client renders active content.
  4. Inject payload: Submit the crafted input through the vulnerable field so that GoAnywhere MFT incorporates it into an outgoing system email without sanitization.
  5. Victim interaction: Wait for the target recipient (e.g., an administrator or partner) to open the system-generated email; the injected HTML renders in their mail client, potentially redirecting them to a phishing page or executing client-side actions.
  6. Achieve objective: Harvest credentials, deliver malware, or conduct further social engineering against the victim (Seclists, NVD).

Indicators of compromise

  • Logs: GoAnywhere MFT audit logs showing unusual or unexpected content in user-controlled fields that are part of email notification templates; outbound email logs containing HTML tags (e.g., <a>, <img>, <script>) in fields that should contain plain text.
  • Network: Outbound HTTP/HTTPS requests from email client systems to unknown or suspicious external domains shortly after opening GoAnywhere-generated notification emails; DNS queries to attacker-controlled domains embedded in injected HTML.
  • Email: System-generated emails from GoAnywhere MFT containing embedded hyperlinks, images, or HTML formatting not consistent with the platform's standard email templates.

Mitigation and workarounds

Fortra has released GoAnywhere MFT version 7.10.0 to address this vulnerability, and organizations should upgrade immediately (Fortra Advisory). No specific configuration-based workaround has been published; the primary remediation is upgrading to version 7.10.0 or later. As a defense-in-depth measure, organizations should configure email clients to render plain text only for system-generated notifications and monitor outbound emails for unexpected HTML content.

Community reactions

SBA Research published a security advisory on April 24, 2026, providing technical details on the HTML injection vulnerability (SBA Research). A full disclosure post was submitted to Seclists in late April 2026 (Seclists). The CVE attracted attention partly due to its initially incorrect description (SFTP brute force), which was corrected by Fortra post-publication, causing some confusion in the security community (NVD).

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management