Insufficient Session Expiration in GoAnywhere MFT - CVE-2026-0971

 

Insufficient Session Expiration in GoAnywhere MFT - CVE-2026-0971

Published: June 19, 2026


Vulnerability identifier: #VU134965
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0971
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose limited sensitive information.

The vulnerability exists due to insufficient session expiration in SAML session handling when a session times out. A remote attacker can cause a victim to interact with the regular login page instead of the SAML login page to disclose limited sensitive information.

User interaction is required.


Affected software

GoAnywhere MFT

How to mitigate CVE-2026-0971

Install security update from vendor's website.

GoAnywhere MFT - update to 7.10.0

External References

Related Security Bulletins