CVE-2024-0204
Authentication Bypass in GoAnywhere MFT
- Published
- Jan 22, 2024
- Updated
- May 30, 2025
- Assigning CNA
- Fortra
- Evidence observed
- May 29, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Sources
4- CVE-2024-0204Exploit
Authentication Bypass in GoAnywhere MFT
- CVE-2024-0204Exploit
This script exploits the CVE-2024-0204 vulnerability in Fortra GoAnywhere MFT, allowing the creation of unauthorized administrative users, for educational and authorized testing purposes.
- CVE-2024-0204Scanner
Python-based scanner for detecting vulnerable GoAnywhere MFT instances affected by CVE-2024-0204, enabling rapid identification and assessment of exposed systems.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.