{"id":"CVE-2025-8148","title":"An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their…","summary":"An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-732","CWE-863"],"vendor":"fortra","product":"goanywhere_managed_file_transfer","affected":["goanywhere_managed_file_transfer < 7.9.0"],"patched":["goanywhere_managed_file_transfer 7.9.0"],"published":"2025-12-05","updated":"2026-09-25","sourceUpdated":"2026-09-25T23:10:00.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8148","references":[{"url":"https://www.fortra.com/security/advisories/product-security/fi-2025-013","label":"df4dee71-de3a-4139-9588-11b62fe6c0ff"}],"tags":["nvd"],"epss":0.00167,"epssPercentile":0.05309,"ingestedAt":"2026-09-25T23:21:16.899Z","slug":"CVE-2025-8148","body":"## Overview\n\nAn Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.\n\n## Affected\n\n- `goanywhere_managed_file_transfer < 7.9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `goanywhere_managed_file_transfer 7.9.0`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}