CVE-2026-0972

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*

History

29 Apr 2026, 20:16

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2026/Apr/8 -

23 Apr 2026, 13:47

Type Values Removed Values Added
References () https://www.fortra.com/security/advisories/product-security/fi-2026-006 - () https://www.fortra.com/security/advisories/product-security/fi-2026-006 - Vendor Advisory
CPE cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*
First Time Fortra
Fortra goanywhere Managed File Transfer

22 Apr 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://fortra.com/security/advisories/product-security/fi-2026-004', 'source': 'df4dee71-de3a-4139-9588-11b62fe6c0ff'}
  • () https://www.fortra.com/security/advisories/product-security/fi-2026-006 -

22 Apr 2026, 16:16

Type Values Removed Values Added
CWE CWE-307 CWE-74
CVSS v2 : unknown
v3 : 7.3
v2 : unknown
v3 : 5.4
Summary (en) The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is configured to log in with an SSH Key, making the SSH key vulnerable to being guessed via Brute Force. (en) HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this CVE were corrected post-publishing.

21 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 15:16

Updated : 2026-04-29 20:16


NVD link : CVE-2026-0972

Mitre link : CVE-2026-0972

CVE.ORG link : CVE-2026-0972


JSON object : View

Products Affected

fortra

  • goanywhere_managed_file_transfer
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')