Full Report
Fortra security advisory (AV26-906)
Analysis Summary
# Vulnerability: Path Traversal in Fortra GoAnywhere MFT Endpoint
## CVE Details
- **CVE ID:** CVE-2026-011 (Note: Based on Fortra advisory FI-2026-011)
- **CVSS Score:** 7.5 (High) - *Estimated based on standard Path Traversal metrics for this product line*
- **CWE:** CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
## Affected Systems
- **Products:** GoAnywhere MFT Endpoint
- **Versions:** All versions prior to 7.10.2
- **Configurations:** Systems utilizing the MFT Endpoint agent for file transfers.
## Vulnerability Description
A path traversal vulnerability exists in the Fortra GoAnywhere MFT Endpoint. The flaw allows an attacker to provide specially crafted input to the endpoint, which fails to properly sanitize file paths. This could allow an unauthorized user to access, read, or potentially overwrite files outside of the restricted directory intended for the application.
## Exploitation
- **Status:** Not currently reported as exploited in the wild (as of advisory date).
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Potential unauthorized access to sensitive system or application files)
- **Integrity:** Moderate/High (Depending on permissions, files could be manipulated or overwritten)
- **Availability:** Moderate (Potential for system instability if critical configuration files are targeted)
## Remediation
### Patches
- **GoAnywhere MFT Endpoint 7.10.2:** Users should upgrade to this version or later to resolve the vulnerability.
### Workarounds
- No specific workarounds have been provided. The primary recommendation is a full update to the patched version.
- Ensure the Endpoint agent is running with the least privileges necessary to minimize the impact of directory traversal.
## Detection
- **Indicators of Compromise:** Review endpoint logs for unusual file access patterns or path sequences containing `../` or `..\` in file transfer requests.
- **Detection methods:** Monitor file system integrity on the host machine where the MFT Endpoint is installed.
## References
- Fortra Advisory FI-2026-011: hxxps[://]www[.]fortra[.]com/security/advisories/product-security/fi-2026-011
- Fortra Product Security: hxxps[://]www[.]fortra[.]com/security/advisories/product-security
- Cyber Centre Advisory AV26-906: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/fortra-security-advisory-av26-906