Improper Restriction of Excessive Authentication Attempts in GoAnywhere MFT - CVE-2025-14362

 

Improper Restriction of Excessive Authentication Attempts in GoAnywhere MFT - CVE-2025-14362

Published: June 19, 2026


Vulnerability identifier: #VU134964
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-14362
CWE-ID: CWE-307
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass login attempt restrictions and guess an SSH key.

The vulnerability exists due to improper restriction of excessive authentication attempts in the SFTP service login mechanism when processing login attempts for a web user configured to authenticate with an SSH key. A remote attacker can send repeated authentication attempts to bypass login attempt restrictions and guess an SSH key.

Only web users configured to log in with an SSH key are affected.


Affected software

GoAnywhere MFT

How to mitigate CVE-2025-14362

Install security update from vendor's website.

GoAnywhere MFT - update to 7.10.0

External References

Related Security Bulletins