SOCLYDE logo
Current languageEN
Cybersecurity newsGoAnywhere MFTFortraCVE

Goanywhere mft: path traversal flaw cve-2026-15913

Fortra fixed a path traversal flaw in GoAnywhere MFT’s /attachRemoteFiles endpoint. Scope, affected versions, and the actions administrators should take.

By Soclyde Team

Isolated file-transfer workstation during a security review

In summary

  • CVE-2026-15913 affects GoAnywhere MFT’s /attachRemoteFiles endpoint before version 7.10.2.
  • A Web User with both Secure Folders and Secure Mail permissions can escape the sandboxed home directory and read arbitrary files.
  • Fortra recommends upgrading to 7.10.2 or later; MFT as a Service customers are described as protected by environmental controls.

Explore next

Soclyde resources

Article contents

On September 9, 2026, Fortra published a security advisory about a path traversal flaw in GoAnywhere MFT. Tracked as CVE-2026-15913, the issue affects the /attachRemoteFiles endpoint and versions before 7.10.2. The Canadian Centre for Cyber Security relayed the alert on September 10.

The documented risk is arbitrary file read through a Web User with a specific combination of permissions. The advisory does not publish a victim list or evidence that a named organisation was exploited: the priority is to check scope and patch without turning a vulnerability advisory into an unverified breach claim.

What Fortra confirmed

Fortra rates the vulnerability High and classifies it as CWE-23 relative path traversal. The issue is in GoAnywhere MFT’s /attachRemoteFiles endpoint. In affected versions, a Web User with both Secure Folders and Secure Mail permissions can escape the sandboxed home directory and read arbitrary files.

The published CVSS score is 7.7, with a network attack vector, low complexity, and required privileges. The score describes potential impact; it does not prove that a file was read in every exposed deployment.

Who should check their deployment

The stated scope is GoAnywhere MFT before version 7.10.2. Inventory should include on-premise installations, standby instances, test environments, and systems operated by an integrator. Verify the product version rather than relying only on whether an administration interface is present.

Fortra says MFT as a Service customers are protected from exploitation through environmental controls. That statement applies to that service model; confirm your deployment type and ask the provider or administrator which version and controls apply to your instance.

The fix and priority checks

The official remediation is to upgrade to GoAnywhere MFT 7.10.2 or later. Before and after the change, record the installed version, correction time, and instances covered. If an upgrade must wait, reduce exposure according to Fortra’s procedures and review Web User accounts that combine the two permissions named in the advisory.

After remediation, search for requests to /attachRemoteFiles, unusual paths, and reads outside the expected directory. Correlate those signals with authentication logs, account ownership, and transfer schedules; no single indicator proves compromise.

What to do if exposure is possible

Preserve logs before rotation and avoid changes that could overwrite useful evidence. Compare observed access with legitimate work performed by Web Users holding Secure Folders and Secure Mail. If abnormal reads are confirmed or strongly suspected, isolate the instance under your response plan, reassess secrets accessible from the server, and involve the people responsible for the investigation.

The documented flaw is a file-read issue; that alone does not establish code execution, complete exfiltration, or compromise of every account. Separating what the advisory proves from what local logs can establish prevents both under- and overestimating the incident.

How Soclyde fits

Soclyde does not patch GoAnywhere MFT, collect its logs, or replace incident response. Its role is around access that may need to be reassessed after exposure: generate unique secrets, keep them in a local-first encrypted vault, and make rotation easier when an administrative or integration account must be replaced.

That separation limits reuse of one secret across GoAnywhere MFT, email, and other services. It does not make a vulnerable instance safe: upgrading, reviewing logs, and investigating exposure remain the priorities.

Key takeaways

CVE-2026-15913 affects /attachRemoteFiles in GoAnywhere MFT before 7.10.2. The documented scenario requires a Web User with Secure Folders and Secure Mail, but can allow escape from the sandbox and arbitrary file reads. Upgrade, review permissions, and search for abnormal access without treating compromise as established.

To reduce the impact of reused secrets during remediation, read the secure password generator guide or contact Soclyde.

Frequently asked questions

Which GoAnywhere MFT versions are affected?

Fortra says versions before 7.10.2 are affected. Verify the version actually deployed, including standby and test environments and instances managed by a service provider.

Can the flaw read every file on the server?

The public description documents escaping the sandboxed home directory and arbitrary file read for a Web User with the two required permissions. It does not establish that every file is reachable or that a particular instance was compromised.

What should I do if a vulnerable instance was exposed?

Upgrade to 7.10.2 or later, preserve logs, and review requests to /attachRemoteFiles together with accounts holding Secure Folders and Secure Mail. If abnormal reads are suspected, preserve evidence and involve your incident-response team.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading