CVE-2025-8148 - CVE House
Back to Database
Status published Medium CVE-2025-8148

CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT

Vulnerability Description

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8148

Credits & Attribution

No credits recorded in the NVD database.