Critical severity9.8NVD Advisory· Published Jan 22, 2024· Updated Jun 17, 2026
CVE-2024-0204
CVE-2024-0204
Description
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*range: >=7.0.0,<7.4.1
- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:6.0.0:*:*:*:*:*:*:*
<7.4.1+ 1 more
- (no CPE)range: <7.4.1
- (no CPE)range: 6.0.1
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.htmlnvdThird Party AdvisoryVDB Entry
- www.fortra.com/security/advisory/fi-2024-001nvdVendor Advisory
- my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtmlnvdPermissions Required
- packetstormsecurity.com/files/176974/Fortra-GoAnywhere-MFT-Unauthenticated-Remote-Code-Execution.htmlnvd
News mentions
0No linked articles in our index yet.