
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0972 is an HTML injection vulnerability in system-generated emails in Fortra's GoAnywhere MFT (Managed File Transfer) affecting all versions prior to 7.10.0. The CVE was initially published on April 21, 2026, with an incorrect description (SFTP brute force) that was corrected post-publishing to reflect the actual HTML injection issue (GitHub Advisory, NVD). The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) as assigned by Fortra, with a changed scope reflecting potential cross-context impact (NVD).
The vulnerability is classified under CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'), specifically manifesting as HTML injection in system-generated emails (NVD). An authenticated attacker with low privileges can inject malicious HTML content into fields that are subsequently included in system-generated email notifications, potentially enabling phishing, content spoofing, or client-side script execution when the email is rendered in a victim's mail client. Exploitation requires user interaction (the recipient opening or viewing the injected email), and the scope is changed, meaning the impact extends beyond the vulnerable GoAnywhere component to the email recipient's environment (GitHub Advisory). A technical write-up was published by SBA Research on April 24, 2026, and a full disclosure post appeared on Seclists (Seclists).
Successful exploitation allows an attacker to inject arbitrary HTML into system-generated emails sent by GoAnywhere MFT, enabling content spoofing, phishing attacks against email recipients, and potentially executing malicious scripts in vulnerable email clients. The confidentiality and integrity impacts are rated as low, with no availability impact, but the changed scope means the attack can affect users beyond the GoAnywhere system itself — particularly employees or partners who receive automated notifications (NVD, GitHub Advisory). This could facilitate credential harvesting or social engineering campaigns targeting users who trust system-generated communications from the MFT platform.
<a href="https://attacker.com">Click here to verify your account</a> or an image tag pointing to an attacker-controlled server for tracking, or a script tag if the email client renders active content.<a>, <img>, <script>) in fields that should contain plain text.Fortra has released GoAnywhere MFT version 7.10.0 to address this vulnerability, and organizations should upgrade immediately (Fortra Advisory). No specific configuration-based workaround has been published; the primary remediation is upgrading to version 7.10.0 or later. As a defense-in-depth measure, organizations should configure email clients to render plain text only for system-generated notifications and monitor outbound emails for unexpected HTML content.
SBA Research published a security advisory on April 24, 2026, providing technical details on the HTML injection vulnerability (SBA Research). A full disclosure post was submitted to Seclists in late April 2026 (Seclists). The CVE attracted attention partly due to its initially incorrect description (SFTP brute force), which was corrected by Fortra post-publication, causing some confusion in the security community (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."