Description
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).

This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
Published: 2026-07-08
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an Improper Neutralization of Special Elements in Data Query Logic in the Custom Reports module of Progress MOVEit Transfer. It allows a user who can create or execute custom reports to craft a query that references database tables outside the intended scope, potentially exposing sensitive data that should otherwise be inaccessible.

Affected Systems

The vulnerability affects Progress MOVEit Transfer versions prior to 2025.0.8 (including 2025.0.0 through 2025.0.7), prior to 2025.1.4 (including 2025.1.0 through 2025.1.3) and prior to 2026.0.1 (including 2026.0.0).

Risk and Exploitability

The CVSS score of 7.2 indicates a moderate to high severity. With an EPSS score of less than 1 % the likelihood of exploitation is considered low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path requires an authenticated user with permission to create or run custom reports; such a user can construct a malicious report definition that retrieves data from tables outside the permitted scope. Successful exploitation would result in the disclosure of confidential information.

Generated by OpenCVE AI on July 29, 2026 at 14:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Progress MOVEit Transfer to version 2025.0.8, 2025.1.4, 2026.0.1, or newer.
  • Restrict or disable the Custom Reports feature for non‑privileged accounts.
  • Limit the MOVEit Transfer service account database privileges to only those tables essential for normal operation.

Generated by OpenCVE AI on July 29, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
Title Table scope bypass vulnerability in custom reports
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T03:55:42.859Z

Reserved: 2026-06-02T16:42:37.519Z

Link: CVE-2026-10698

cve-icon Vulnrichment

Updated: 2026-07-08T15:09:33.633Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:15:03Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic