An Improper Access Control in the SFTP service in Fortra...
Moderate severity
Unreviewed
Published
Dec 5, 2025
to the GitHub Advisory Database
•
Updated Dec 5, 2025
Description
Published by the National Vulnerability Database
Dec 5, 2025
Published to the GitHub Advisory Database
Dec 5, 2025
Last updated
Dec 5, 2025
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
References