HackerFeeds
All CVEs

CVE-2026-15913

HIGH7.7

Published 2026-09-09 · Source df4dee71-de3a-4139-9588-11b62fe6c0ff

Description

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CWE-23
View on NVD