Improper Neutralization of Special Elements in Output Used by a Downstream Component in GoAnywhere MFT - CVE-2026-0972

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in GoAnywhere MFT - CVE-2026-0972

Published: June 19, 2026


Vulnerability identifier: #VU134967
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0972
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject HTML content into system generated emails.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in system generated emails when generating email content. A remote user can inject crafted HTML content to inject HTML content into system generated emails.

User interaction is required to view the generated email content.


Affected software

GoAnywhere MFT

How to mitigate CVE-2026-0972

Install security update from vendor's website.

GoAnywhere MFT - update to 7.10.0

External References

Related Security Bulletins