CVE-2026-15913 (GCVE-0-2026-15913)
Vulnerability from cvelistv5
Published
2026-09-09 21:18
Modified
2026-09-10 13:49
CWE
  • CWE-23 - Relative path traversal
Summary
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
Impacted products
Vendor Product Version
Fortra GoAnywhere MFT Version: 0   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-15913",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-10T13:49:14.002969Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-10T13:49:34.773Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "modules": [
            "Secure Mail",
            "Secure Folders",
            "File System"
          ],
          "product": "GoAnywhere MFT",
          "vendor": "Fortra",
          "versions": [
            {
              "lessThan": "7.10.2",
              "status": "affected",
              "version": "0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "reporter",
          "value": "xtromera (Zerosploit) https://www.zerosploit.co/"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "ZeyadZonkorany (Zerosploit) https://www.zerosploit.co/"
        },
        {
          "lang": "en",
          "type": "reporter",
          "value": "0xkalawy (Zerosploit) https://www.zerosploit.co/"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "In versions prior to 7.10.2 a path traversal vulnerability in the\u0026nbsp;/attachRemoteFiles endpoint\u0026nbsp;of Fortra\u0027s GoAnywhere MFT allows Web Users with both\u0026nbsp;Secure Folders and Secure Mail permissions\u0026nbsp;to escape their sandboxed home directory, achieving arbitrary file read."
            }
          ],
          "value": "In versions prior to 7.10.2 a path traversal vulnerability in the\u00a0/attachRemoteFiles endpoint\u00a0of Fortra\u0027s GoAnywhere MFT allows Web Users with both\u00a0Secure Folders and Secure Mail permissions\u00a0to escape their sandboxed home directory, achieving arbitrary file read."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-126",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-126 Path Traversal"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-23",
              "description": "CWE-23 Relative path traversal",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-09T21:18:54.261Z",
        "orgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
        "shortName": "Fortra"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.fortra.com/security/advisories/product-security/fi-2026-011"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Upgrade to a remediated version (version 7.10.2 or later)."
            }
          ],
          "value": "Upgrade to a remediated version (version 7.10.2 or later)."
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Path Traversal in Fortra\u0027s GoAnywhere MFT Endpoint",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "df4dee71-de3a-4139-9588-11b62fe6c0ff",
    "assignerShortName": "Fortra",
    "cveId": "CVE-2026-15913",
    "datePublished": "2026-09-09T21:18:54.261Z",
    "dateReserved": "2026-07-15T19:34:18.897Z",
    "dateUpdated": "2026-09-10T13:49:34.773Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"cna\": {\"providerMetadata\": {\"orgId\": \"df4dee71-de3a-4139-9588-11b62fe6c0ff\", \"shortName\": \"Fortra\", \"dateUpdated\": \"2026-09-09T21:18:54.261Z\"}, \"title\": \"Path Traversal in Fortra\u0027s GoAnywhere MFT Endpoint\", \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"cweId\": \"CWE-23\", \"description\": \"CWE-23 Relative path traversal\", \"type\": \"CWE\"}]}], \"impacts\": [{\"capecId\": \"CAPEC-126\", \"descriptions\": [{\"lang\": \"en\", \"value\": \"CAPEC-126 Path Traversal\"}]}], \"affected\": [{\"vendor\": \"Fortra\", \"product\": \"GoAnywhere MFT\", \"modules\": [\"Secure Mail\", \"Secure Folders\", \"File System\"], \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"7.10.2\", \"versionType\": \"semver\"}], \"defaultStatus\": \"unaffected\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"In versions prior to 7.10.2 a path traversal vulnerability in the\\u00a0/attachRemoteFiles endpoint\\u00a0of Fortra\u0027s GoAnywhere MFT allows Web Users with both\\u00a0Secure Folders and Secure Mail permissions\\u00a0to escape their sandboxed home directory, achieving arbitrary file read.\", \"supportingMedia\": [{\"type\": \"text/html\", \"base64\": false, \"value\": \"In versions prior to 7.10.2 a path traversal vulnerability in the\u0026nbsp;/attachRemoteFiles endpoint\u0026nbsp;of Fortra\u0027s GoAnywhere MFT allows Web Users with both\u0026nbsp;Secure Folders and Secure Mail permissions\u0026nbsp;to escape their sandboxed home directory, achieving arbitrary file read.\"}]}], \"references\": [{\"url\": \"https://www.fortra.com/security/advisories/product-security/fi-2026-011\", \"tags\": [\"vendor-advisory\"]}], \"metrics\": [{\"format\": \"CVSS\", \"scenarios\": [{\"lang\": \"en\", \"value\": \"GENERAL\"}], \"cvssV3_1\": {\"version\": \"3.1\", \"attackVector\": \"NETWORK\", \"attackComplexity\": \"LOW\", \"privilegesRequired\": \"LOW\", \"userInteraction\": \"NONE\", \"scope\": \"CHANGED\", \"confidentialityImpact\": \"HIGH\", \"integrityImpact\": \"NONE\", \"availabilityImpact\": \"NONE\", \"baseSeverity\": \"HIGH\", \"baseScore\": 7.7, \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N\"}}], \"solutions\": [{\"lang\": \"en\", \"value\": \"Upgrade to a remediated version (version 7.10.2 or later).\", \"supportingMedia\": [{\"type\": \"text/html\", \"base64\": false, \"value\": \"Upgrade to a remediated version (version 7.10.2 or later).\"}]}], \"credits\": [{\"lang\": \"en\", \"value\": \"xtromera (Zerosploit) https://www.zerosploit.co/\", \"type\": \"reporter\"}, {\"lang\": \"en\", \"value\": \"ZeyadZonkorany (Zerosploit) https://www.zerosploit.co/\", \"type\": \"reporter\"}, {\"lang\": \"en\", \"value\": \"0xkalawy (Zerosploit) https://www.zerosploit.co/\", \"type\": \"reporter\"}], \"source\": {\"discovery\": \"UNKNOWN\"}, \"x_generator\": {\"engine\": \"Vulnogram 1.0.5\"}}, \"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2026-15913\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2026-09-10T13:49:14.002969Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2026-09-10T13:49:20.827Z\"}}]}",
      "cveMetadata": "{\"cveId\": \"CVE-2026-15913\", \"assignerOrgId\": \"df4dee71-de3a-4139-9588-11b62fe6c0ff\", \"state\": \"PUBLISHED\", \"assignerShortName\": \"Fortra\", \"dateReserved\": \"2026-07-15T19:34:18.897Z\", \"datePublished\": \"2026-09-09T21:18:54.261Z\", \"dateUpdated\": \"2026-09-10T13:49:34.773Z\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…