CVE-2026-49244 | drakkan SFTPGo up to 2.7.2 Public Web-Client Partial ZIP Download Endpoint path traversal

SecurityVulns

A vulnerability was found in drakkan SFTPGo up to 2.7.2 and classified as problematic. Affected is an unknown function of the component Public Web-Client Partial ZIP Download Endpoint. Executing a manipulation can lead to path traversal.

The identification of this vulnerability is CVE-2026-49244. The attack may be launched remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More