Impact
This vulnerability in Progress MOVEit Transfer permits the refreshing of authentication tokens without enforcing updated account restrictions, enabling a session to remain valid beyond its intended lifespan. Such a flaw can result in an attacker maintaining unauthorized access after a user’s account has been modified, potentially giving them an extended window to exploit the system.
Affected Systems
Products affected include Progress MOVEit Transfer versions before 2025.1.5 and the 2026.0.0 releases up to, but not including, 2026.0.3. Organizations should verify the exact build numbers in their installations to determine if the environment is vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known. Based on the description, the likely attack vector involves the web interface that issues refresh tokens; an attacker who obtains a session could use that session to continue interacting with the system after account restrictions have been applied.
OpenCVE Enrichment