CVE-2026-15913

Summary

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

Affected Software

VendorProductVersion RangeStatus
FortraGoAnywhere MFT0 < 7.10.2affected

Weaknesses

  • CWE-23: CWE-23 Relative path traversal

References