๐Ÿ” CVE Alert

CVE-2026-30914

UNKNOWN 0.0

SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder. This vulnerability is fixed in 2.7.1.

CWE CWE-22
Vendor drakkan
Product sftpgo
Published Mar 13, 2026
Last Updated Mar 13, 2026
Stay Ahead of the Next One

Get instant alerts for drakkan sftpgo

Be the first to know when new unknown vulnerabilities affecting drakkan sftpgo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

drakkan / sftpgo
< 2.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/drakkan/sftpgo/security/advisories/GHSA-x8qh-7475-c5mp