Improper Data Handling in MOVEit Transfer by Progress Software
CVE-2026-8649

6.4MEDIUM

Key Information:

Vendor

Progress

Vendor
CVE Published:
8 July 2026

What is CVE-2026-8649?

An improper data handling issue exists in Progress MOVEit Transfer, particularly within its Custom Reports modules. This vulnerability can lead to unintended access or manipulation of data as the system fails to properly neutralize special elements in query logic. Versions of MOVEit Transfer prior to 2025.0.7 and from 2025.1.0 up to, but not including, 2025.1.3 are susceptible to these security concerns. Organizations utilizing these versions should assess their systems promptly to mitigate any potential risks.

Affected Version(s)

MOVEit Transfer 2025.1.0 < 2025.1.3

MOVEit Transfer 0 < 2025.0.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Levy
.