Impact
The vulnerability arises from an improper CORS configuration that allows any domain to send requests to the server. Because the server accepts requests from untrusted origins, an attacker can host a malicious website that forces a victim’s browser to interact with MOVEit, potentially reading or modifying data. This flow allows unauthorized data disclosure or manipulation and is classified as CWE‑942, affecting confidentiality and integrity of the files managed by MOVEit.
Affected Systems
Products impacted include Progress MOVEit Transfer versions before 2025.1.5 and the 2026.x line prior to 2026.0.3. Any instance running these older releases is vulnerable. Upgrading to at least 2025.1.5 or any 2026.0.3 release or later removes the flaw.
Risk and Exploitability
The CVSS base score of 7.5 classifies the vulnerability as High. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attack. The likely attack vector requires a victim’s browser to load a malicious domain that performs cross‑origin requests to the MOVEit server, thus privileged users or those authenticated to MOVEit while browsing the web are the primary risk. The vendor’s fix in the 2026.0.3 release eliminates the permissive CORS setting.
OpenCVE Enrichment