Description
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
Problem types
CWE-276 Incorrect default permissions
Product status
Any version before 2025.0.11
2025.1.0 (semver) before 2025.1.7
Credits
Airbus SecLab
Anaïs Gantet
Delphine Gourdou
Quentin Liddell
Matteo Ricordeau
References
docs.progress.com/...-notes-2026/page/Fixed-Issues-2026.html