CVE-2024-25157: Fortra GoAnywhere Managed File Transfer

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

Affected products

  • Fortra GoAnywhere Managed File Transfer: before 7.6.0 (fixed in 7.6.0)

Published 2024-08-14. Last modified 2026-06-17.