CVE-2025-8148 Overview
CVE-2025-8148 is an improper access control vulnerability [CWE-732] in the Secure File Transfer Protocol (SFTP) service of Fortra's GoAnywhere Managed File Transfer (MFT). The flaw affects versions prior to 7.9.0. Web Users configured with an Authentication Alias and a valid Secure Shell (SSH) key can authenticate using their SSH key even when their account is restricted to Password authentication for SFTP. The vulnerability stems from the SFTP service failing to enforce the configured authentication method restriction. Fortra published the issue in security advisory FI-2025-013.
Critical Impact
Authenticated Web Users can bypass password-only authentication enforcement by presenting an SSH key, undermining the intended authentication policy on the SFTP service.
Affected Products
- Fortra GoAnywhere Managed File Transfer versions prior to 7.9.0
- SFTP service component of GoAnywhere MFT
- Web User accounts configured with Authentication Alias and SSH key material
Discovery Timeline
- 2025-12-05 - CVE-2025-8148 published to the National Vulnerability Database (NVD)
- 2026-09-25 - Last updated in NVD database
Technical Details for CVE-2025-8148
Vulnerability Analysis
GoAnywhere MFT supports multiple authentication mechanisms for Web Users accessing the SFTP service, including password and public key authentication. Administrators can configure a Web User with an Authentication Alias and restrict allowed SFTP authentication to Password only. The SFTP service does not consistently honor this restriction. If the Web User also has a valid SSH key associated with their account, the server accepts SSH key-based authentication despite the configured policy. The outcome is an authentication method confusion between the configured policy and the SFTP service's accepted credentials.
This weakens defense-in-depth controls for environments that intentionally disable key-based authentication, for example to enforce password rotation, multi-factor flows, or alias-based identity mapping. Exploitation requires an attacker to already possess a valid SSH key tied to a Web User account, limiting the scope to insider misuse or environments where key material has been exposed.
Root Cause
The root cause is incorrect permission assignment [CWE-732] in the SFTP authentication handler. The handler evaluates the presence of a valid SSH key independently of the Web User's configured allowed authentication methods. The policy enforcement check for Password-only SFTP users is missing or incorrectly ordered in the authentication state machine.
Attack Vector
The attack vector is network-based and requires low privileges because the attacker must present a valid SSH key associated with a provisioned Web User. An attacker with the SSH private key material connects to the SFTP service and completes publickey authentication. The service grants the session even though the Web User policy specifies password as the only permitted method. No user interaction is required.
No verified public exploit code is available. See the Fortra Security Advisory FI-2025-013 for vendor technical details.
Detection Methods for CVE-2025-8148
Indicators of Compromise
- SFTP authentication events in GoAnywhere audit logs showing publickey method success for Web Users whose configuration restricts SFTP to password authentication.
- Successful SSH key logins from source IP addresses or geographies that do not match historical password-based login patterns for the same account.
- Unexpected file transfer activity following an SFTP session established via SSH key for a Password-only account.
Detection Strategies
- Audit the GoAnywhere Web User configuration export and correlate each account's allowed SFTP authentication methods against actual authentication methods observed in SFTP session logs.
- Alert on any SFTP session where the negotiated authentication method does not match the account's configured policy.
- Review all accounts that have both an Authentication Alias and an associated SSH key, and verify whether key-based access is intended.
Monitoring Recommendations
- Forward GoAnywhere MFT audit logs to a centralized logging or SIEM platform and build detections on authentication-method mismatches.
- Monitor the SFTP service for first-time SSH key use per account and for authentication from new source IP ranges.
- Track administrative changes to Web User authentication settings and SSH key assignments.
How to Mitigate CVE-2025-8148
Immediate Actions Required
- Upgrade Fortra GoAnywhere MFT to version 7.9.0 or later as directed in Fortra Security Advisory FI-2025-013.
- Inventory all Web Users that have SSH keys assigned and verify whether key-based SFTP access is required for each account.
- Rotate or revoke SSH keys that are no longer required or that may have been exposed.
Patch Information
Fortra addressed CVE-2025-8148 in GoAnywhere MFT 7.9.0. The vendor advisory FI-2025-013 is the authoritative source for patch availability and upgrade guidance. Apply the update in test environments first and validate SFTP authentication behavior for all Web User policy variants before production rollout.
Workarounds
- Remove SSH public keys from Web User accounts that are intended to authenticate only with passwords until the upgrade is applied.
- Restrict network access to the SFTP service to known administrative networks while the patch is being deployed.
- Enable detailed SFTP authentication logging and review for publickey logins on Password-only accounts.
# Example: identify Web Users with SSH keys using the GoAnywhere admin interface
# 1. Navigate to Users > Web Users
# 2. Filter by "SSH Key: Assigned"
# 3. Cross-reference with accounts whose SFTP authentication is set to Password only
# 4. Remove the SSH key assignment or upgrade to GoAnywhere MFT 7.9.0+
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.