Information Disclosure Vulnerability in Fortra GoAnywhere MFT
A vulnerability in Fortra GoAnywhere MFT allows a remote, authenticated attacker to disclose sensitive information due to insufficient access control.
CVE search metadata
CVE search record: CVE-2024-8674. KEV: no. Product: GoAnywhere MFT. Brief: Information Disclosure Vulnerability in Fortra GoAnywhere MFT. Brief link: https://feed.craftedsignal.io/briefs/2026-09-fortra-goanywhere-mft-vulnerability/
Fortra has released a security advisory regarding a vulnerability in GoAnywhere MFT, a managed file transfer solution. The flaw allows a remote, authenticated attacker to bypass existing security controls and perform unauthorized information disclosure. This issue highlights a weakness in access control mechanisms within the application that could lead to the exposure of sensitive data stored or processed by the system. While the advisory specifies that the attacker must be authenticated, this poses a significant risk to organizations where internal credentials may be compromised or where excessive privileges are granted to service accounts. Defenders should identify instances of Fortra GoAnywhere MFT and ensure they are patched to the vendor-recommended version to mitigate unauthorized data access risks associated with CVE-2024-8674.
Impact
The vulnerability results in unauthorized disclosure of sensitive information handled by the GoAnywhere MFT platform. If exploited, an attacker could gain access to potentially confidential files, system configurations, or user metadata, compromising the integrity of data transfers within the affected environment.
Recommendation
- Identify all internet-facing or internal deployments of Fortra GoAnywhere MFT within the asset inventory.
- Review the official vendor security bulletin for CVE-2024-8674 to identify the specific patched version required for your environment.
- Audit user access logs and permission configurations within the GoAnywhere MFT application to ensure the principle of least privilege is enforced for all authenticated accounts.
- Monitor application access logs for anomalous, high-volume data retrieval requests from authenticated service accounts or standard users.
Immediate actions
Inventory all GoAnywhere MFT instances and verify current version against vendor patch requirements for CVE-2024-8674.
Mitigations
Apply the latest security patch provided by Fortra for GoAnywhere MFT to address CVE-2024-8674.
CVE-2024-8674