CVE-2026-49245 | drakkan SFTPGo up to 2.7.2 File Download cookie httponly flag

SecurityVulns

A vulnerability was found in drakkan SFTPGo up to 2.7.2. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Download. The manipulation leads to cookie without ‘httponly’ flag.

This vulnerability is referenced as CVE-2026-49245. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More