PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49245 drakkan CVE debrief

CVE-2026-49245 is a vulnerability in SFTPGo, an open-source file transfer solution, that allows an attacker to serve an HTML file as text/html, potentially leading to execution in the victim's browser context. The issue arises from the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppressing Content-Disposition: attachment. This can be exploited by an attacker who can place an HTML file in a share or home directory, and then send a crafted link to a victim. The victim, upon opening the link, may execute the stored content in their browser context. Exploitation requires social engineering and suitable share or shared-folder access.

Vendor
drakkan
Product
sftpgo
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-20
Original CVE updated
2026-09-18
Advisory published
2026-08-20
Advisory updated
2026-09-18

Who should care

Defenders responsible for SFTPGo deployments, particularly those with shared or browsable file transfers, should assess exposure and apply the fix. This includes reviewing SFTPGo configurations, monitoring for suspicious activity, and ensuring that compensating controls are in place for exposed systems.

Why it matters

CVE-2026-49245 allows an attacker to serve an HTML file as text/html in SFTPGo, potentially leading to execution in the victim's browser context. Defenders should prioritize verifying exposure and applying the fix.

  • Potential execution of attacker-controlled content in victim's browser context
  • Requires social engineering and suitable share or shared-folder access
  • Limited direct cookie theft due to HttpOnly session cookies

Technical summary

The inline query parameter on browsable-share file downloads and authenticated user-file downloads in SFTPGo suppresses Content-Disposition: attachment, allowing an attacker-controlled HTML file to be served as text/html. This issue can be exploited by an attacker who can place an HTML file in a share or home directory and then send a crafted link to a victim. The victim, upon opening the link, may execute the stored content in their browser context. The vulnerability is fixed in version 2.7.3, and defenders should prioritize verifying exposure and applying the fix.

Defensive priority

Defenders should prioritize verifying exposure and applying the fix, as exploitation requires social engineering and suitable share or shared-folder access.

Recommended defensive actions

  • Verify exposure by checking SFTPGo versions and configurations
  • Apply the fix by upgrading to version 2.7.3
  • Monitor for suspicious activity and potential social engineering attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, the scope of affected versions and potential impact on specific deployments require verification. The issue is fixed in version 2.7.3. Additional verification steps include reviewing SFTPGo configurations and monitoring for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49245 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49245

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49245 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49245

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.