SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15913

HIGH · CVSS 7.7 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Fortra's GoAnywhere MFT prior to version 7.10.2 allows authenticated Web Users with Secure Folders and Secure Mail permissions to access files outside their designated home directory, potentially leading to unauthorized file disclosure. Organizations utilizing this software, particularly those with sensitive data management needs, should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-15913
Severity
HIGH
CVSS
7.7
EPSS
0.39%

Original NVD Description

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.