CVE-2026-15913: Path Traversal in Fortra's GoAnywhere MFT Endpoint
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fortra GoAnywhere MFTto a version that resolves this vulnerability.Fixed in 7.10.2
Event History
Frequently Asked Questions
Which users and deployments are exposed?
Affected deployments are GoAnywhere MFT versions prior to 7.10.2 where a Web User has both Secure Folders and Secure Mail permissions. Exploitation targets the /attachRemoteFiles endpoint.
What access does an attacker need to exploit this issue?
An attacker needs Web User access and must have both Secure Folders and Secure Mail permissions. No user interaction is required.
What is the impact of successful exploitation?
A successful attacker can escape the Web User's sandboxed home directory and read arbitrary files.
How can this be remediated?
Upgrade GoAnywhere MFT to version 7.10.2 or later. If an upgrade cannot be performed immediately, limit the combination of Secure Folders and Secure Mail permissions for Web Users.