CVE-2026-40884: Critical 9.8 Bypass Hits goshs SFTP Servers
ID: df3a9ba8-f9a9-565e-b25f-fc3b3495df1d
STIX ID: report--df3a9ba8-f9a9-565e-b25f-fc3b3495df1d
Feed Name: securityonline.info
Threat Score
A critical authentication bypass (CVE-2026-40884, CVSS 9.8) was found in goshs: when SFTP is enabled and a password is set with an empty username using -b':pass', the server accepts connections but never installs the SFTP password handler, allowing unauthenticated access to the entire exposed root. The flaw was reproduced on v2.0.0-beta.5 and affects all prior releases; users are advised to upgrade to v2.0.0-beta.6 or later and audit their SFTP configuration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
