Insufficient Session Expiration in GoAnywhere MFT - CVE-2026-0971
Published: June 19, 2026
GoAnywhere MFT
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose limited sensitive information.
The vulnerability exists due to insufficient session expiration in SAML session handling when a session times out. A remote attacker can cause a victim to interact with the regular login page instead of the SAML login page to disclose limited sensitive information.
User interaction is required.