{"id":"CVE-2026-30914","aliases":["GHSA-x8qh-7475-c5mp","GO-2026-4699"],"url":"https://o3.security/vulnerability/CVE-2026-30914","summary":"SFTPGo has a Path Traversal and Permission Bypass via Path Normalization Discrepancy","details":"### Impact\n\nIn SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protocol handlers and the internal Virtual Filesystem routing can lead to an authorization bypass. An authenticated attacker can craft specific file paths to bypass folder-level permissions or escape the boundaries of a configured Virtual Folder.\n\n\n### Patches\n\nThis issue has been addressed in SFTPGo version 2.7.1. The fix introduces strict edge-level path normalization, ensuring that all protocol inputs are fully sanitized and resolved to canonical POSIX paths before any routing or permission evaluations occur.","published":"2026-03-13T19:02:28.270Z","modified":"2026-08-12T03:51:16.650021329Z","cvss":null,"epss":{"score":0.00521,"percentile":0.4303,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/drakkan/sftpgo/v2","fixedVersion":"2.7.1"},{"ecosystem":"Go","name":"github.com/drakkan/sftpgo","fixedVersion":null}],"fix":{"url":"https://github.com/drakkan/sftpgo/commit/2f092d128917e2c059520a2ce3e22c3b5ea7ffd6","label":"drakkan/sftpgo@2f092d1"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30914.json"},{"type":"ADVISORY","url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-x8qh-7475-c5mp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30914"},{"type":"WEB","url":"https://github.com/drakkan/sftpgo/commit/2f092d128917e2c059520a2ce3e22c3b5ea7ffd6"},{"type":"PACKAGE","url":"https://github.com/drakkan/sftpgo"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4699"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.650021329Z"}}