Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mcantrell

#31778de 53,633
8.1CVSS total
Vulnerabilidades · 1
PT-2026-25354
8.1
2026-03-13
Sftpgo · Sftpgo · CVE-2026-30914
**Name of the Vulnerable Software and Affected Versions** SFTPGo versions prior to 2.7.1 **Description** SFTPGo is an open-source, event-driven file transfer solution. A path normalization discrepancy exists between the protocol handlers and the internal Virtual Filesystem routing in versions prior to 2.7.1. This discrepancy can lead to an authorization bypass. An authenticated attacker can create specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder. **Recommendations** Update to SFTPGo version 2.7.1 or later.