CVE-2026-49244 | drakkan SFTPGo up to 2.7.2 Public Web-Client Partial ZIP Download Endpoint path traversal
A vulnerability was found in drakkan SFTPGo up to 2.7.2 and classified as problematic. Affected is an unknown function of the component Public Web-Client Partial ZIP Download Endpoint. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-49244. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More