CVE-2026-15913

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 22:17

Updated : 2026-09-10 15:53


NVD link : CVE-2026-15913

Mitre link : CVE-2026-15913

CVE.ORG link : CVE-2026-15913


JSON object : View

Products Affected

No product.

CWE
CWE-23

Relative Path Traversal