Improper Authentication Flaw in MOVEit Transfer by Progress
CVE-2026-10697

7.5HIGH

Key Information:

Vendor

Progress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-10697?

The MOVEit Transfer application by Progress has a security flaw due to improper authentication which affects users of specific older versions. This vulnerability allows an unauthorized user to gain access, potentially compromising sensitive data. Users running MOVEit Transfer versions prior to 2025.1.5 and from 2026.0.0 to below 2026.0.3 are specifically at risk. It is vital for administrators to upgrade their installations to ensure enhanced security and protect against potential exploitation.

Affected Version(s)

MOVEit Transfer 0 < 2025.1.5

MOVEit Transfer 2026.0.0 < 2026.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Levy
.