A high-severity authentication bypass in goshs lets remote users access the built-in SFTP service without credentials under a specific startup configuration. Tracked as CVE-2026-62325, the flaw affects versions 2.1.3 through before 2.1.4 and occurs when goshs is launched with a username and empty password, such as:
-b 'admin:' -sftp
If the service is also started without configured authorized keys, the SFTP password authentication handler may never be registered, leaving the underlying gliderlabs/ssh framework to permit anonymous access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A fix for CVE-2026-62325 was released in goshs version 2.1.4. The vulnerability allowed unauthenticated SFTP access when goshs was run with a username and empty password and no authorized keys configured.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.