CVE-2015-2856: Accellion File Transfer Appliance

High severity, CVSS 7.5. EPSS: 56.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.

Affected products

  • Accellion File Transfer Appliance: up to and including fta_9_11_200

Published 2017-10-10. Last modified 2026-06-17.