Impact
The vulnerability is an improper authentication flaw that, when exploited, enables bypassing MFA and unauthorized access to MOVEit Transfer. It is classified as CWE-287, but the CVE description does not detail further effects on data or administrative controls.
Affected Systems
Progress MOVEit Transfer installations before version 2025.1.5, as well as releases from 2026.0.0 up to but not including 2026.0.3, are vulnerable. All corporate users and system administrators who rely on MFA for portal access are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV, indicating no confirmed public exploits. The flaw allows bypassing MFA authentication, potentially allowing unauthorized access. However, the CVE description does not provide details on the exact attack pathway, so it is inferred that an attacker might need valid user credentials or other means to reach the authentication endpoint.
OpenCVE Enrichment