Description
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module).

This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Published: 2026-07-08
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization flaw in the AuditUser module of Progress MOVEit Transfer that allows users granted the AuditUser role to information and therefore breaches confidentiality. The weakness is a missing authentication/authorization defect (CWE‑863).

Affected Systems

The affected vendor is Progress, product MOVEit Transfer. Versions before 2025.0.7 and from 2025.1.0 up to but not including 2025.1.3 are vulnerable.

Risk and Exploitability

The CVSS score of 2.7 indicates low overall severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated session with a user possessing the AuditUser role, so the threat is internal or arises from compromised credentials rather than remote exploitation.

Generated by OpenCVE AI on July 29, 2026 at 13:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Progress MOVEit Transfer to version 2025.0.7 or newer, and to 2025.1.3 or newer to resolve the authorization flaw.
  • Review and restrict permissions associated with the AuditUser role to prevent access to external token metadata.
  • Enable or review audit logs for anomalous access to token metadata and investigate any unauthorized occurrences.

Generated by OpenCVE AI on July 29, 2026 at 13:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Title Cross-Org External Token Metadata accessible to AuditUser role
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T13:35:24.535Z

Reserved: 2026-05-18T02:42:58.378Z

Link: CVE-2026-8800

cve-icon Vulnrichment

Updated: 2026-07-09T13:35:16.259Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T13:45:02Z

Weaknesses