Relative Path Traversal in GoAnywhere MFT - CVE-2026-15913
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose arbitrary files outside the sandboxed home directory.
The vulnerability exists due to relative path traversal in the /attachRemoteFiles endpoint when handling requests to attach remote files. A remote user can submit a crafted path traversal request to disclose arbitrary files outside the sandboxed home directory.
Exploitation requires both Secure Folders and Secure Mail permissions.