{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-0971","assignerOrgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","state":"PUBLISHED","assignerShortName":"Fortra","dateReserved":"2026-01-14T22:56:32.772Z","datePublished":"2026-04-21T14:14:23.423Z","dateUpdated":"2026-04-21T19:26:58.470Z"},"containers":{"cna":{"providerMetadata":{"orgId":"df4dee71-de3a-4139-9588-11b62fe6c0ff","shortName":"Fortra","dateUpdated":"2026-04-21T14:14:23.423Z"},"title":"GoAnywhere MFT SAML Sessions do not redirect to logout URL on session timeout","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-613","description":"CWE-613 Insufficient session expiration","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}],"affected":[{"vendor":"Fortra","product":"GoAnywhere MFT","platforms":["Windows","MacOS","Linux"],"versions":[{"status":"affected","version":"0","lessThan":"7.10.0","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page.","supportingMedia":[{"type":"text/html","base64":false,"value":"An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web Users being redirected to the regular login page instead of the SAML login page."}]}],"references":[{"url":"https://fortra.com/security/advisories/product-security/fi-2025-013"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"}}],"solutions":[{"lang":"en","value":"Update to version 7.10.0 or higher of GoAnywhere MFT","supportingMedia":[{"type":"text/html","base64":false,"value":"Update to version 7.10.0 or higher of GoAnywhere MFT"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.1"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-04-21T19:26:48.832583Z","id":"CVE-2026-0971","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-04-21T19:26:58.470Z"}}]}}