Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module).

This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Published: 2026-07-08
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in Progress MOVEit Transfer’s Ad Hoc module leads to a stored cross‑site scripting vulnerability (CWE‑79). An attacker who can submit malicious payloads that are later rendered in a victim’s browser could execute arbitrary JavaScript. The resulting impact may include session hijacking, theft of credentials, or other actions that compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

Affected releases include all Progress MOVEit Transfer versions before 2026.0.1, before 2025.1.4, and before 2025.0.8.

Risk and Exploitability

The flaw carries a CVSS score of 8, classifying it as high risk. Its EPSS score of < 1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the web interface of the Ad‑Hoc module, where a user can submit content that is stored and subsequently rendered to other users; no privileges beyond module access are required.

Generated by OpenCVE AI on August 1, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MOVEit Transfer to a fixed release – for 2026.x use 2026.0.1 or later; for 2025.1.x use 2025.1.4; for 2025.0.x use 2025.0.8.
  • Apply any relevant security patches released by Progress after the fixed releases.
  • Disable or restrict access to the Ad Hoc module until an update is applied, or implement a strict content‑security‑policy to block injected scripts.

Generated by OpenCVE AI on August 1, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Title Stored XSS in MOVEit Transfer Ad Hoc module
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T03:55:41.919Z

Reserved: 2026-06-10T15:50:46.983Z

Link: CVE-2026-11903

cve-icon Vulnrichment

Updated: 2026-07-08T15:13:55.163Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T15:16:25.470

Modified: 2026-07-10T14:01:59.527

Link: CVE-2026-11903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T16:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')