CVE-2026-30914 identifies an authorization bypass vulnerability in SFTPGo versions prior to 2.7.1, caused by a path normalization discrepancy. An authenticated attacker can exploit this by crafting specific file paths to bypass folder-level permissions or escape virtual folder boundaries, leading to high confidentiality and integrity impacts. Rated 8.1 HIGH on the CVSS scale, this flaw is remotely exploitable with low complexity, requiring only low privileges. There is no known active exploitation or public exploit code available, though a SUSE security update indicates some community awareness. Organizations using affected SFTPGo versions should upgrade to 2.7.1 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.7.1CPE matchmatch criteria | cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.