PatchSiren cyber security CVE debrief
CVE-2026-49245 drakkan CVE debrief
CVE-2026-49245 is a vulnerability in SFTPGo, an open-source file transfer solution, that allows an attacker to serve an HTML file as text/html, potentially leading to execution in the victim's browser context. The issue arises from the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppressing Content-Disposition: attachment. This can be exploited by an attacker who can place an HTML file in a share or home directory, and then send a crafted link to a victim. The victim, upon opening the link, may execute the stored content in their browser context. Exploitation requires social engineering and suitable share or shared-folder access.
- Vendor
- drakkan
- Product
- sftpgo
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-20
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-20
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for SFTPGo deployments, particularly those with shared or browsable file transfers, should assess exposure and apply the fix. This includes reviewing SFTPGo configurations, monitoring for suspicious activity, and ensuring that compensating controls are in place for exposed systems.
Why it matters
CVE-2026-49245 allows an attacker to serve an HTML file as text/html in SFTPGo, potentially leading to execution in the victim's browser context. Defenders should prioritize verifying exposure and applying the fix.
- Potential execution of attacker-controlled content in victim's browser context
- Requires social engineering and suitable share or shared-folder access
- Limited direct cookie theft due to HttpOnly session cookies
Technical summary
The inline query parameter on browsable-share file downloads and authenticated user-file downloads in SFTPGo suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file to be served as text/html. This issue can be exploited by an attacker who can place an HTML file in a share or home directory and then send a crafted link to a victim. The victim, upon opening the link, may execute the stored content in their browser context. The vulnerability is fixed in version 2.7.3, and defenders should prioritize verifying exposure and applying the fix.
Defensive priority
Defenders should prioritize verifying exposure and applying the fix, as exploitation requires social engineering and suitable share or shared-folder access.
Recommended defensive actions
- Verify exposure by checking SFTPGo versions and configurations
- Apply the fix by upgrading to version 2.7.3
- Monitor for suspicious activity and potential social engineering attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, the scope of affected versions and potential impact on specific deployments require verification. The issue is fixed in version 2.7.3. Additional verification steps include reviewing SFTPGo configurations and monitoring for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49245 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49245
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49245 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49245
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/drakkan/sftpgo/commit/b5409a478138fca5f1d369ae5d47f753156cbd15
-
Source reference
Unverified legacy reference
URL: https://github.com/drakkan/sftpgo/releases/tag/v2.7.3
-
Source reference
Unverified legacy reference
URL: https://github.com/drakkan/sftpgo/security/advisories/GHSA-3vcg-pv95-pq54
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.