Description
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).

This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Published: 2026-07-08
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the vulnerability is a relative path traversal flaw in the Admin Settings module of Progress MOVEit Transfer that allows users with administrative privileges to request and read arbitrary files on the host system. This flaw permits viewing of any file readable by the MOVEit service, potentially exposing confidential data. The weakness is identified as CWE-23, indicating its use for unauthorized information disclosure.

Affected Systems

The affected products are Progress MOVEit Transfer. Versions prior to 2025.0.7 and versions from 2025.1.0 up to, but not including, 2025.1.3 are vulnerable. All other released versions are presumed unaffected.

Risk and Exploitability

Based on the available data, the likely attack vector is an authenticated request to the MOVEit admin interface, requiring administrative privileges. The CVSS score of 4.5 places the issue in a Medium severity level, and an EPSS score of < 1% indicates an extremely low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation results in confidentiality compromise of system files, with no immediate denial of service or code execution.

Generated by OpenCVE AI on July 26, 2026 at 17:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to MOVEit Transfer version 2025.0.7 or newer for 2025.0.x releases, and to 2025.1.3 or newer for 2025.1.x releases.
  • If an upgrade is not immediately possible, limit administrative access by disabling the file view functionality or restricting the MOVE request capability to a narrower set of users. Ensure that only a minimal number of trusted administrators retain such permissions.
  • Monitor system logs for anomalous file access attempts and revoke any compromised administrative credentials.

Generated by OpenCVE AI on July 26, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Title Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T13:31:57.971Z

Reserved: 2026-05-15T04:28:13.041Z

Link: CVE-2026-8650

cve-icon Vulnrichment

Updated: 2026-07-09T13:31:53.184Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:15:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal