PT-2026-66629 · Sftpgo · Sftpgo

·

CVE-2026-10031

·

Published

2026-07-30

·

Updated

2026-07-31

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.7.4
Description Authenticated users can bypass per-directory access controls by creating symbolic links in a permitted directory that point to files in restricted directories where download, upload, or overwrite permissions are denied. By leveraging the create symlinks permission along with read and write access in a permitted directory, an attacker can read or modify files in restricted areas because the system authorizes operations based on the link's directory permissions instead of the permissions of the dereferenced target directory.
Recommendations Update to version 2.7.4 or later. Restrict the use of the create symlinks permission to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10031
GHSA-FJ9V-MXR3-W75W

Affected Products

Sftpgo