We are announcing the latest release of SFTPPlus version 3.55.0.

We are announcing the latest release of SFTPPlus version 3.55.0.
This release includes a critical security issue for the Local Manager's web console GUI introduced with SFTPPlus version 3.24.0.
The vulnerability is a local one if Local Manager only accepts local connections, as configured by default.
Your SFTPPlus setup is not affected if you are not using the default-enabled "Store in database" event handler.
In order to audit for potential security breaches, parse the log files for events with ID 50026 and check them for any unauthorized access. Unfortunately, you can only identify unauthorized access by its timestamp.
No user data or passwords can be compromised this way. The usernames and file names are found in the logs and can be exposed to unauthorized parties.
To fix this security issue, you need to upgrade SFTPPlus to version 3.55.0.
If you can't upgrade right away, you should harden the configuration by deleting the "Store in database" event handlers. If you would rather keep using this feature without updating, make sure the Local Manager is only available through secured channels such as a VPN tunnel.
You can check the full release notes here.