CVE-2026-15913
GoAnywhere MFT vulnerability analysis and mitigation

Overview

CVE-2026-15913 is a relative path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT that allows authenticated Web Users to escape their sandboxed home directory and achieve arbitrary file read. It affects all versions of GoAnywhere MFT prior to 7.10.2. The vulnerability was published on September 9, 2026, with a patch advisory released by Fortra the same day. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Fortra Advisory).

Technical details

The vulnerability is classified as CWE-23 (Relative Path Traversal), where the /attachRemoteFiles endpoint fails to properly neutralize path sequences (e.g., ../) in user-supplied input, allowing directory traversal outside the intended sandboxed home directory. Exploitation requires an authenticated Web User account that holds both Secure Folders and Secure Mail permissions — a specific combination of privileges that grants access to the vulnerable endpoint. The attack is network-based, requires low privileges, no user interaction, and results in a scope change, enabling access to files beyond the attacker's authorized directory (GitHub Advisory, Fortra Advisory).

Impact

Successful exploitation allows an authenticated attacker to read arbitrary files on the GoAnywhere MFT server outside their sandboxed directory, resulting in high confidentiality impact with no integrity or availability impact. Sensitive data such as configuration files, credentials, private keys, or managed file transfer data stored on the server could be exposed. Given GoAnywhere MFT's role as a managed file transfer platform, the potential for sensitive business or customer data disclosure is significant (GitHub Advisory, Fortra Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with a specific combination of permissions (Secure Folders and Secure Mail), which somewhat limits the attack surface.

Exploitation steps

  1. Reconnaissance: Identify GoAnywhere MFT instances running versions prior to 7.10.2 exposed to the network. Confirm the target version via login page banners or HTTP response headers.
  2. Obtain credentials: Acquire or use existing Web User credentials that have both Secure Folders and Secure Mail permissions assigned — the specific permission combination required to access the vulnerable endpoint.
  3. Authenticate: Log in to the GoAnywhere MFT web interface using the obtained credentials to establish an authenticated session.
  4. Craft traversal request: Send a crafted HTTP request to the /attachRemoteFiles endpoint, embedding relative path traversal sequences (e.g., ../../etc/passwd or ../../conf/goanywhere.properties) in the relevant parameter to escape the sandboxed home directory.
  5. Read arbitrary files: The server processes the traversal sequence without proper sanitization, returning the contents of the targeted file outside the user's authorized directory, enabling disclosure of sensitive server files (GitHub Advisory, Fortra Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to the /attachRemoteFiles endpoint containing path traversal sequences such as ../, %2e%2e%2f, or %2e%2e/ in request parameters.
  • Logs: GoAnywhere MFT access logs showing requests to /attachRemoteFiles with encoded or literal directory traversal patterns; file access log entries referencing paths outside expected user home directories.
  • Behavior: Web User accounts with Secure Folders and Secure Mail permissions making unexpected file access requests, particularly to system configuration directories or sensitive file paths not associated with normal MFT operations.

Mitigation and workarounds

Fortra has released GoAnywhere MFT version 7.10.2 which addresses this vulnerability; upgrading to 7.10.2 or later is the recommended remediation (Fortra Advisory). As a workaround, administrators should review and restrict Secure Folders and Secure Mail permissions, granting both only to users who strictly require them, thereby reducing the pool of accounts that can reach the vulnerable endpoint. Additionally, monitoring the /attachRemoteFiles endpoint in access logs for suspicious path traversal patterns can help detect exploitation attempts.

Additional resources


SourceThis report was generated using AI

Related GoAnywhere MFT vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15913HIGH7.7
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesSep 09, 2026
CVE-2025-14362HIGH7.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-1089MEDIUM6.5
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0972MEDIUM5.4
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026
CVE-2026-0971MEDIUM4.3
  • GoAnywhere MFT logoGoAnywhere MFT
  • cpe:2.3:a:fortra:goanywhere_managed_file_transfer
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management