
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15913 is a relative path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT that allows authenticated Web Users to escape their sandboxed home directory and achieve arbitrary file read. It affects all versions of GoAnywhere MFT prior to 7.10.2. The vulnerability was published on September 9, 2026, with a patch advisory released by Fortra the same day. It carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory, Fortra Advisory).
The vulnerability is classified as CWE-23 (Relative Path Traversal), where the /attachRemoteFiles endpoint fails to properly neutralize path sequences (e.g., ../) in user-supplied input, allowing directory traversal outside the intended sandboxed home directory. Exploitation requires an authenticated Web User account that holds both Secure Folders and Secure Mail permissions — a specific combination of privileges that grants access to the vulnerable endpoint. The attack is network-based, requires low privileges, no user interaction, and results in a scope change, enabling access to files beyond the attacker's authorized directory (GitHub Advisory, Fortra Advisory).
Successful exploitation allows an authenticated attacker to read arbitrary files on the GoAnywhere MFT server outside their sandboxed directory, resulting in high confidentiality impact with no integrity or availability impact. Sensitive data such as configuration files, credentials, private keys, or managed file transfer data stored on the server could be exposed. Given GoAnywhere MFT's role as a managed file transfer platform, the potential for sensitive business or customer data disclosure is significant (GitHub Advisory, Fortra Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with a specific combination of permissions (Secure Folders and Secure Mail), which somewhat limits the attack surface.
/attachRemoteFiles endpoint, embedding relative path traversal sequences (e.g., ../../etc/passwd or ../../conf/goanywhere.properties) in the relevant parameter to escape the sandboxed home directory./attachRemoteFiles endpoint containing path traversal sequences such as ../, %2e%2e%2f, or %2e%2e/ in request parameters./attachRemoteFiles with encoded or literal directory traversal patterns; file access log entries referencing paths outside expected user home directories.Fortra has released GoAnywhere MFT version 7.10.2 which addresses this vulnerability; upgrading to 7.10.2 or later is the recommended remediation (Fortra Advisory). As a workaround, administrators should review and restrict Secure Folders and Secure Mail permissions, granting both only to users who strictly require them, thereby reducing the pool of accounts that can reach the vulnerable endpoint. Additionally, monitoring the /attachRemoteFiles endpoint in access logs for suspicious path traversal patterns can help detect exploitation attempts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."