PT-2026-55446 · Sftpgo · Sftpgo

CVE-2026-49244

·

Published

2026-07-02

·

Updated

2026-08-21

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.7.3
Description A path confinement bypass exists in the public web-client endpoint used for partial ZIP downloads of browsable shares. The system failed to correctly restrict client-supplied file entries to the intended shared directory. This allows a requester to read files located outside the shared directory, provided the target's canonical path starts with the name of the shared directory.
Recommendations Update to version 2.7.3.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49244
GHSA-H64P-8H4R-6GFH
GO-2026-5902
OPENSUSE-SU-2026:21483-1

Affected Products

Sftpgo