Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer.

This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Published: 2026-07-23
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation in Progress MOVEit Transfer. An attacker who can inject malicious scripts into the application’s persistent data will cause those scripts to be executed in the browsers of other users who view the affected content. This can lead to session hijacking, credential theft, defacement, or other client‑side compromise. The weakness is catalogued as CWE‑79, indicating an input validation issue.

Affected Systems

The affected product is Progress MOVEit Transfer. All releases prior to 2025.1.5 and the 2026 range from 2026.0.0 up through (but not including) 2026.0.3 are vulnerable. All newer releases post‑2026.0.3 or the 2025.1.5+ iterations contain the fix.

Risk and Exploitability

The CVSS score of 7.1 categorises this as high severity. Its EPSS score is below 1 %, meaning the probability of exploitation at the current time is low but not zero. The vulnerability is not listed in the CISA KEV catalog. The likely attack path requires a user to submit input that is stored by the application and later displayed to others, making the exploitation web‑based and user‑interaction dependent.

Generated by OpenCVE AI on August 3, 2026 at 21:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MOVEit Transfer to version 2026.0.3 or later, or to 2025.1.5 or newer if using an earlier major line.
  • If an upgrade cannot be performed immediately, enforce strict input sanitisation on all fields that can store data and escape script content before rendering it back to clients.
  • Implement monitoring for anomalous script tags or JavaScript inserted into stored data, and review logs for suspicious user input that could be related to cross‑site scripting attempts.

Generated by OpenCVE AI on August 3, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Title Stored XSS vulnerability in MOVEit Transfer
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-24T13:32:48.089Z

Reserved: 2026-07-16T15:15:02.130Z

Link: CVE-2026-15968

cve-icon Vulnrichment

Updated: 2026-07-24T13:32:43.531Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T21:17:03.090

Modified: 2026-07-30T15:49:28.140

Link: CVE-2026-15968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')