Improper Neutralization of Special Elements in Output Used by a Downstream Component in GoAnywhere MFT - CVE-2026-0972
Published: June 19, 2026
GoAnywhere MFT
Detailed vulnerability description
The vulnerability allows a remote user to inject HTML content into system generated emails.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in system generated emails when generating email content. A remote user can inject crafted HTML content to inject HTML content into system generated emails.
User interaction is required to view the generated email content.