CVE-2026-0971

An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*

History

23 Apr 2026, 14:00

Type Values Removed Values Added
First Time Fortra
Fortra goanywhere Managed File Transfer
References () https://fortra.com/security/advisories/product-security/fi-2025-013 - () https://fortra.com/security/advisories/product-security/fi-2025-013 - Not Applicable
CPE cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*

21 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 15:16

Updated : 2026-04-23 14:00


NVD link : CVE-2026-0971

Mitre link : CVE-2026-0971

CVE.ORG link : CVE-2026-0971


JSON object : View

Products Affected

fortra

  • goanywhere_managed_file_transfer
CWE
CWE-613

Insufficient Session Expiration