CVE Vulnerabilities

CVE-2026-0971

Insufficient Session Expiration

Published: Apr 21, 2026 | Modified: Apr 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An improper session timeout issue in Fortras GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

NameVendorStart VersionEnd Version
Goanywhere_managed_file_transferFortra*7.10.0 (excluding)

Potential Mitigations

References