CVE-2026-0971: medium-severity vulnerability in Fortra GoAnywhere MFT
GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.3epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected products
Fortra · GoAnywhere MFTRelated CVEs — Fortra GoAnywhere MFT
In the same product, most dangerous first.
CVE-2025-10035CRITICALDeserialization Vulnerability in GoAnywhere MFT's License ServletEPSS 99.8%KEVCVE-2024-0204CRITICALAuthentication Bypass in GoAnywhere MFTEPSS 95.1%CVE-2024-25157MEDIUMAuthentication bypass in GoAnywhere MFT prior to 7.6.0EPSS 0.5%CVE-2026-15913HIGHPath Traversal in Fortra's GoAnywhere MFT EndpointEPSS 0.4%CVE-2024-25156MEDIUMPath traversal in GoAnywhere MFT 7.4.1 and EarlierEPSS 0.4%CVE-2025-3871MEDIUMBroken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlierEPSS 0.4%