Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module).

This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Published: 2026-07-08
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input during web Progress MOVEit Transfer, classified as a Stored XSS flaw (CWE‑79). An attacker who can submit malicious input that is later rendered in a victim’s browser could execute arbitrary scripts, potentially allowing session hijacking, theft of sensitive data, or other malicious actions that threaten confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected versions include all releases of Progress MOVEit Transfer before 2026.0.1, before 2025.1.4, and before 2025.0.8.

Risk and Exploitability

With a CVSS score of 8 the vulnerability is considered high risk, and the EPSS score of < 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely attack vector is the web interface of the Ad‑Hoc module, where a user can submit content that is stored and later rendered to other users; no special privileges beyond module access are required.

Generated by OpenCVE AI on July 29, 2026 at 14:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MOVEit Transfer to a fixed release – for 2026.x use 2026.0.1 or later; for 2025.1.x use 2025.1.4; for 2025.0.x use 2025.0.8.
  • Apply any relevant security patches released by Progress after the fixed releases.
  • Disable or restrict access to the Ad Hoc module until an update is applied, or implement a strict content‑security‑policy to block injected scripts.

Generated by OpenCVE AI on July 29, 2026 at 14:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Title Stored XSS in MOVEit Transfer Ad Hoc module
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T03:55:41.919Z

Reserved: 2026-06-10T15:50:46.983Z

Link: CVE-2026-11903

cve-icon Vulnrichment

Updated: 2026-07-08T15:13:55.163Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')