Unverified Password Change Vulnerability in Progress MOVEit Transfer
CVE-2025-11235

3.7LOW

Key Information:

Vendor

Progress

Vendor
CVE Published:
6 January 2026

What is CVE-2025-11235?

This vulnerability in Progress MOVEit Transfer affects various versions, allowing unauthorized password changes without proper verification. An attacker could leverage this flaw to gain control over user accounts, posing significant security risks. The affected versions include MOVEit Transfer from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, and from 2022.0.0 before 2022.0.10. Organizations using these versions should apply necessary patches to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MOVEit Transfer Windows 2023.1.0 < 2023.1.3

MOVEit Transfer Windows 2023.0.0 < 2023.0.8

MOVEit Transfer Windows 2022.1.0 < 2022.1.11

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aden Yap Chuen Zhen, BAE SYSTEM Digital Intelligence
.