Back

MEDIUM

Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier

Published Jul 16, 2025

Description

Broken access control in Fortra's GoAnywhere MFT prior to 7.8.1 allows an attacker to create a denial of service situation when configured to use GoAnywhere One-Time Password (GOTP) email two-factor authentication (2FA) and the user has not set an email address. In this scenario, the attacker may enter the email address of a known user when prompted and the user will be disabled if that user has configured GOTP.

Affected products

Remediation

Vendor solution

Upgrade to GoAnwhere MFT 7.8.1 or higher

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fortra
Published Jul 16, 2025
Updated Jul 18, 2025
Reserved Apr 22, 2025
CISA Vulnrichment
Updated Jul 18, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Fortra
Published Jul 16, 2025
Updated Jul 18, 2025
Exploited since n/a
EUVD-2025-21703