Path Traversal Exposure in MOVEit Transfer by Progress Software
CVE-2026-8650

4.5MEDIUM

Key Information:

Vendor

Progress

Vendor
CVE Published:
8 July 2026

What is CVE-2026-8650?

A relative path traversal vulnerability exists in the Admin Settings module of Progress MOVEit Transfer, which can potentially allow an attacker to access files and directories outside of the intended file system path. Affected versions include those prior to 2025.0.7 and from 2025.1.0 but before 2025.1.3. Proper security measures should be implemented to safeguard sensitive data against unauthorized access.

Affected Version(s)

MOVEit Transfer 2025.1.0 < 2025.1.3

MOVEit Transfer 0 < 2025.0.7

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Niv Levy
.