Description
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Problem types
CWE-20 Improper input validation
Product status
2025.1.0 (semver) before 2025.1.5
2025.0.0 (semver) before 2025.0.9
2024.0.0 (semver) before 2024.1.8
Any version before 2024.0.0
Credits
Airbus SecLab
Anaïs Gantet
Delphine Gourdou
Quentin Liddell
Matteo Ricordeau
References
community.progress.com/...l-2026-CVE-2026-4670-CVE-2026-5174