An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

Project Subscriptions

Vendors Products
Goanywhere Mft Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update to version 7.10.0 or higher of GoAnywhere MFT


Workaround

No workaround given by the vendor.

History

Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra goanywhere Mft
Vendors & Products Fortra
Fortra goanywhere Mft

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Description An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
Title GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2026-04-21T19:26:58.470Z

Reserved: 2026-01-14T22:56:32.772Z

Link: CVE-2026-0971

cve-icon Vulnrichment

Updated: 2026-04-21T19:26:53.216Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-21T15:16:35.717

Modified: 2026-04-21T16:20:24.180

Link: CVE-2026-0971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T11:46:28Z

Weaknesses