An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
History

Fri, 05 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 21:15:00 +0000


Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
Description An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.
Title CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Weaknesses CWE-732
CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published: 2025-12-05T20:56:05.135Z

Updated: 2025-12-05T21:48:44.070Z

Reserved: 2025-07-24T21:27:23.294Z

Link: CVE-2025-8148

cve-icon Vulnrichment

Updated: 2025-12-05T21:48:39.950Z

cve-icon NVD

Status : Received

Published: 2025-12-05T21:15:54.907

Modified: 2025-12-05T21:15:54.907

Link: CVE-2025-8148

cve-icon Redhat

No data.