Description
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).

This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Published: 2026-07-08
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in MOVEit Transfer’s file upload modules is a CWE‑46 weakness that allows a file extension restriction bypass by exploiting path equivalence. An attacker can craft file names to upload malicious content be placed on the system and potentially compromising integrity.

Affected Systems

Progress MOVEit Transfer versions prior to 2025.0.8 and between 2025.1.0 and before 2025.1.4 are affected. Any environment running one of those releases is potentially vulnerable.

Risk and Exploitability

Based on the description, the exploit likely occurs through the web upload interface, a vector that is externally reachable and requires only user interaction. With a CVSS score of 3.5 the issue rates as low severity, and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. While the exploit conditions are straightforward, the low severity and lack of widespread exploitation evidence suggest this vulnerability is not an immediate threat, is advisable.

Generated by OpenCVE AI on July 26, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Progress MOVEit Transfer to version 2025.0.8 or later, or to 2025.1.4 or later, as detailed in the vendor’s release notes.
  • Ensure that the file upload configuration enforces strict extension filtering and only allows the expected file types.
  • Regularly inspect upload logs for anomalous file names or unexpected file types and verify that no unauthorized files have been placed on the server.

Generated by OpenCVE AI on July 26, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress moveit Transfer
Vendors & Products Progress
Progress moveit Transfer

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Description Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Title File Extension Restriction Bypass in MOVEit Transfer
Weaknesses CWE-46
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Progress Moveit Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-09T13:36:42.815Z

Reserved: 2026-05-18T02:43:00.228Z

Link: CVE-2026-8801

cve-icon Vulnrichment

Updated: 2026-07-09T13:36:07.399Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T17:15:04Z

Weaknesses
  • CWE-46

    Path Equivalence: 'filename ' (Trailing Space)