Insufficient Session Expiration in MOVEit Transfer by Progress
CVE-2026-15967

7.5HIGH

Key Information:

Vendor

Progress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-15967?

The vulnerability in Progress MOVEit Transfer arises from insufficient session expiration, which could allow unauthorized users to maintain session access beyond expected time limits. This flaw affects versions prior to 2025.1.5, as well as from 2026.0.0 to just before 2026.0.3, potentially exposing sensitive user data to unauthorized access if proper session management protocols are not enforced.

Affected Version(s)

MOVEit Transfer 0 < 2025.1.5

MOVEit Transfer 2026.0.0 < 2026.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.