An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to version 7.10.0 or higher of GoAnywhere MFT
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page. | |
| Title | GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fortra
Published:
Updated: 2026-04-21T14:14:23.423Z
Reserved: 2026-01-14T22:56:32.772Z
Link: CVE-2026-0971
No data.
Status : Awaiting Analysis
Published: 2026-04-21T15:16:35.717
Modified: 2026-04-21T16:20:24.180
Link: CVE-2026-0971
No data.
OpenCVE Enrichment
No data.
Weaknesses