CVE Feed

    Dashboard / CVE / CVE-2026-30915

    CVE-2026-30915

    SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation issue in the handling of dynamic group paths, for example, home directories or key prefixes. When a group is configured with a dynamic home directory or key prefix using placeholders like %username%, the value replacing the placeholder is not strictly sanitized against relative path components. Consequently, if a user is created with a specially crafted username the resulting path may resolve to a parent directory instead of the intended sub-directory. This issue is fixed in version v2.7.1

    Published:Mar 13, 2026
    Last Modified:Mar 23, 2026
    EPS:Mar 13, 2026
    EPSS Score:0.00059
    CVSS Score:4.3

    Affected Products

    Vendor
    Drakkan
    Product
    Sftpgo
    Vendor
    Sftpgo Project
    Product
    Sftpgo

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High