CVE-2026-49244: Drakkan Sftpgo

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison rather than a directory-boundary-aware check. An unauthenticated requester who can reach a public share can select a canonical path outside the shared directory when the target path begins with the shared directory's name, such as a sibling path that shares the same prefix. The endpoint then includes the out-of-scope file in the generated download, disclosing its contents. This issue is fixed in version 2.7.3.

Affected products

  • Drakkan Sftpgo: from 2.2.0, before 2.7.2 (fixed in 2.7.2)

Published 2026-08-20. Last modified 2026-09-18.