Back to Database
Status published
Medium
CVE-2025-8148
CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Vulnerability Description
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8148
Credits & Attribution
No credits recorded in the NVD database.
More from Fortra
View All →CVE-2025-8450
Unrestricted File Upload in FileCatalyst
High
8.2
CVE-2025-5141
Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
Medium
5.5
CVE-2025-3871
Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier
Medium
5.3
CVE-2025-1241
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Medium
5.8
CVE-2025-14362
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
High
7.3
Affected Vendor
Fortra
View all reports →Affected Software
GoAnywhere MFT
Vulnerable Versions:
0
Timeline
Official Publish:
December 5th, 2025
Last Modified:
December 5th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
MITRE ATT&CK TTPs
T1222
File and Directory Permissions Modification
Defense Evasion
T1574
Hijack Execution Flow
Privilege Escalation
T1005
Data from Local System
Collection
T1078
Valid Accounts
Persistence
T1562
Impair Defenses
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1021
Remote Services
Lateral Movement
T1098
Account Manipulation
Defense Evasion