Improper Data Handling in MOVEit Transfer by Progress Software
CVE-2026-8649
6.4MEDIUM
What is CVE-2026-8649?
An improper data handling issue exists in Progress MOVEit Transfer, particularly within its Custom Reports modules. This vulnerability can lead to unintended access or manipulation of data as the system fails to properly neutralize special elements in query logic. Versions of MOVEit Transfer prior to 2025.0.7 and from 2025.1.0 up to, but not including, 2025.1.3 are susceptible to these security concerns. Organizations utilizing these versions should assess their systems promptly to mitigate any potential risks.
Affected Version(s)
MOVEit Transfer 2025.1.0 < 2025.1.3
MOVEit Transfer 0 < 2025.0.7
