Description
Insufficient session expiration vulnerability in Progress MOVEit Transfer.

This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Progress MOVEit Transfer permits the refreshing of authentication tokens without enforcing updated account restrictions, enabling a session to remain valid beyond its intended lifespan. Such a flaw can result in an attacker maintaining unauthorized access after a user’s account has been modified, potentially giving them an extended window to exploit the system.

Affected Systems

Products affected include Progress MOVEit Transfer versions before 2025.1.5 and the 2026.0.0 releases up to, but not including, 2026.0.3. Organizations should verify the exact build numbers in their installations to determine if the environment is vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known. Based on the description, the likely attack vector involves the web interface that issues refresh tokens; an attacker who obtains a session could use that session to continue interacting with the system after account restrictions have been applied.

Generated by OpenCVE AI on August 3, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MOVEit Transfer release (2026.0.3 or newer) to enforce proper token expiration and account restriction checks.
  • Ensure that session expiration policies are applied consistently and that changes to account status are reflected in active sessions.
  • If a patch cannot be deployed immediately, disable or restrict the use of refresh tokens until the official fix is applied and monitor for anomalous authentication activity.

Generated by OpenCVE AI on August 3, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Title MOVEit Transfer refresh-token processing does not enforce updated account restrictions
Weaknesses CWE-613
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-25T03:55:22.642Z

Reserved: 2026-07-16T15:15:01.159Z

Link: CVE-2026-15967

cve-icon Vulnrichment

Updated: 2026-07-24T13:33:46.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T21:17:02.977

Modified: 2026-07-30T15:50:12.613

Link: CVE-2026-15967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:15:04Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration