---
id: CVE-2026-15913
title: "In versions prior to 7.10.2 a path traversal vulnerability in the\_/attachRemoteFiles endpoint\_of Fortra's GoAnywhere MFT allows Web Users with both\_Secure Folders and Secure Mail permissions\_to escape their sandboxed home directory, achi…"
summary: "In versions prior to 7.10.2 a path traversal vulnerability in the\_/attachRemoteFiles endpoint\_of Fortra's GoAnywhere MFT allows Web Users with both\_Secure Folders and Secure Mail permissions\_to escape their sandboxed home directory, achi…"
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-23
vendor: Fortra
product: GoAnywhere MFT
affected:
  - goanywhere_mft < 7.10.2
published: '2026-09-09'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15913'
references:
  - url: 'https://www.fortra.com/security/advisories/product-security/fi-2026-011'
    label: df4dee71-de3a-4139-9588-11b62fe6c0ff
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T13:49:14.002969Z'
ingestedAt: '2026-09-09T21:22:45.593Z'
epss: 0.00393
epssPercentile: 0.3077
---

## Overview

In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
