Description
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Problem types
CWE-305 Authentication bypass by primary weakness
Product status
2025.0.0 (semver) before 2025.0.9
2024.0.0 (semver) before 2024.1.8
Any version before 2024.0.0
Credits
Airbus SecLab
Anaïs Gantet
Delphine Gourdou
Quentin Liddell
Matteo Ricordeau
References
community.progress.com/...l-2026-CVE-2026-4670-CVE-2026-5174