A critical authentication bypass vulnerability in Fortra GoAnywhere MFT allows unauthenticated attackers to create a new administrative user by directly accessing the /InitialAccountSetup.xhtml endpoint. Tracked as CVE-2024-0204, the flaw stems from improper path normalization and affects versions earlier than 7.4.1. Public reporting said most observed internet-exposed instances were still running vulnerable releases, raising the risk of opportunistic compromise.
Fortra and defenders urged organizations to upgrade immediately to GoAnywhere MFT 7.4.1 or later. As a temporary mitigation for non-containerized deployments, administrators were advised to remove the vulnerable setup page and restart services:
rm -f $GOANYWHERE_INSTALL_DIR/adminroot/WEB-INF/classes/com/linoma/ga/ui/admin/InitialAccountSetup.xhtml
The issue was identified by Mohammed Eldeeb and Islam Elrfai of Spark Engineering Consultants, and technical analysis showed the bug could be abused to regain access to an initialization workflow that should no longer be reachable after first-time setup.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A critical authentication bypass vulnerability, CVE-2024-0204, was identified in Fortra GoAnywhere MFT by Mohammed Eldeeb and Islam Elrfai of Spark Engineering Consultants. The flaw affects versions earlier than 7.4.1 and can let an unauthenticated attacker create a new administrative user via the /InitialAccountSetup.xhtml endpoint.
On 2024-02-05, CSIRT.SK published a notice about CVE-2024-0204, stating that 96.4% of observed GoAnywhere instances were running a vulnerable version. The advisory recommended upgrading to GoAnywhere MFT 7.4.1 or later, or temporarily removing InitialAccountSetup.xhtml and restarting services in non-containerized deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.