CVE-2026-0971

MEDIUM

GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout

Title source: cna
STIX 2.1

Description

An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (2)
Fortra/GoAnywhere MFT < 7.10.0
fortra/goanywhere_managed_file_transfer < 7.10.0
Published Apr 21, 2026
Tracked Since Apr 21, 2026