CVE-2026-62325 is an authentication bypass vulnerability in goshs affecting versions 2.1.3 through 2.1.4 prior to the fix in 2.1.4. The flaw is in the SFTP server initialization logic in sftpserver/sftpserver.go, where registration of the password authentication handler depended on the condition Username != "" && Password != "". When goshs is started with SFTP enabled and basic-auth style credentials containing a valid username but an empty password, the condition evaluates false and the password handler is not registered. If public-key authentication is also not configured, both SFTP authentication handlers remain unset. In that state, the underlying SSH framework permits anonymous access, resulting in unauthenticated access to the SFTP service. The issue is described as an incomplete fix related to CVE-2026-40884.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An improper authentication vulnerability in goshs SFTP server configuration that can leave authentication handlers unset and allow unauthenticated file access.
An authentication bypass vulnerability in an SFTP/file server where supplying a username with an empty password can prevent authentication handlers from being registered, causing the underlying SSH framework to allow anonymous access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.