CVE-2026-1089
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2026-1089 is a User-Controlled HTTP Header vulnerability in Fortra's GoAnywhere Managed File Transfer (MFT) that allows unauthenticated attackers to trigger arbitrary DNS lookups, conduct DNS rebinding attacks, and cause information disclosure. It affects all versions of GoAnywhere MFT prior to 7.10.0. The CVE was received from Fortra on April 21, 2026, with initial NVD analysis completed on April 23, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Fortra (GitHub Advisory, Fortra Advisory).

Technical details

The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'). The vulnerability arises because GoAnywhere MFT fails to properly validate or sanitize user-supplied HTTP header values before using them in downstream operations, allowing an attacker to inject values that cause the server to perform DNS lookups to attacker-controlled domains. This network-accessible flaw requires no authentication, no user interaction, and has low attack complexity, making it straightforward to trigger remotely. The primary attack techniques enabled are DNS rebinding — which can be used to bypass same-origin policy protections and pivot to internal network resources — and information disclosure via DNS side-channels (Fortra Advisory, GitHub Advisory).

Impact

Successful exploitation results in low confidentiality impact (partial information disclosure) and low availability impact, with no integrity impact. An unauthenticated remote attacker can force the GoAnywhere MFT server to issue DNS queries to attacker-controlled infrastructure, potentially revealing internal network topology, server IP addresses, or other sensitive metadata via DNS side-channels. DNS rebinding attacks could further allow an attacker to bypass browser same-origin restrictions and interact with internal services accessible to the GoAnywhere MFT host, increasing the risk of lateral movement within the network (Fortra Advisory, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing GoAnywhere MFT instances running versions prior to 7.10.0 using tools such as Shodan or Censys, searching for GoAnywhere MFT banners or known web interface paths.
  2. Set up attacker-controlled DNS infrastructure: Register a domain and configure a DNS server to log all incoming DNS queries, enabling detection of server-side DNS lookups.
  3. Craft malicious HTTP request: Send an HTTP request to the GoAnywhere MFT application with a user-controlled header (e.g., Host, X-Forwarded-For, Referer, or a similar header) set to a value pointing to the attacker's domain (e.g., attacker.example.com).
  4. Trigger DNS lookup: The server processes the injected header value and issues a DNS lookup to the attacker-controlled domain, which is logged by the attacker's DNS server — confirming the vulnerability and potentially revealing the server's egress IP.
  5. DNS Rebinding (advanced): Configure the attacker's DNS server to initially resolve to a legitimate IP, then rapidly change the DNS response to an internal IP address. Exploit this to bypass same-origin policy and interact with internal services accessible from the GoAnywhere MFT host, potentially accessing internal APIs or administrative interfaces.

Indicators of compromise

  • Network: Unexpected outbound DNS queries from the GoAnywhere MFT server to external or unusual domains not associated with normal operations; DNS queries containing encoded or suspicious subdomains (e.g., random strings used as DNS exfiltration channels).
  • Logs: GoAnywhere MFT application logs showing HTTP requests with anomalous or externally-controlled values in headers such as Host, X-Forwarded-For, Referer, or custom headers; repeated requests from the same source IP with varying header values targeting DNS-resolvable hostnames.
  • Network: Outbound connections from the GoAnywhere MFT server to unexpected IP addresses following DNS resolution of attacker-controlled domains, which may indicate successful DNS rebinding and follow-on access attempts.

Mitigation and workarounds

Fortra has released GoAnywhere MFT version 7.10.0 to address this vulnerability; all users should upgrade immediately (Fortra Advisory). For systems that cannot be patched immediately, implement network-level egress filtering to restrict outbound DNS queries from the GoAnywhere MFT server to only trusted, necessary resolvers. Additionally, restrict network access to the GoAnywhere MFT application from untrusted or external sources using firewall rules or network segmentation to reduce the attack surface.

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2025-1241MEDIUM4.9
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management