CVE-2026-30914: SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy

Published Mar 13, 2026
·
Updated

Impact

In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder.

Patches

This issue has been addressed in SFTPGo version 2.7.1. The fix introduces strict edge-level path normalization, ensuring that all protocol inputs are fully sanitized and resolved to canonical POSIX paths before any routing or permission evaluations occur.

Other sources

SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder. This vulnerability is fixed in 2.7.1.

MITRE

Affected Software

3 affected componentsFixes available
go/github.com/drakkan/sftpgo<=1.2.2
go/github.com/drakkan/sftpgo/v2<=2.7.0
2.7.1
Sftpgo Project Sftpgo<2.7.1

Event History

Mar 13, 2026
Advisory Published
via GitHub·06:55 PM
Data Sourced
via GitHub·06:55 PM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionWeakness
Data Sourced
via NVD·07:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:54 PM
Affected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-30914?

CVE-2026-30914 has a high severity due to the potential for unauthorized access to restricted file paths.

2

How do I fix CVE-2026-30914?

To fix CVE-2026-30914, upgrade SFTPGo to version 2.7.1 or later.

3

What versions of SFTPGo are affected by CVE-2026-30914?

SFTPGo versions prior to 2.7.1, including 1.2.2 and all versions in the 2.7.0 range, are affected by CVE-2026-30914.

4

What type of vulnerability is CVE-2026-30914?

CVE-2026-30914 is a path traversal and permission bypass vulnerability.

5

Can CVE-2026-30914 be exploited by an unauthenticated attacker?

No, CVE-2026-30914 requires authentication to exploit, as it involves an authorized user's actions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203