Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NProgress Moveit Automation
APPProgress< 2025.0.112025.1.0 – 2025.1.7 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2026-4670CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w Progress MOVEit Automation (CVE-2026-4670)
CVE-2026-5174HIGH7.7same product
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. T...
CVE-2026-8485MEDIUM5.9same product
Podatność związana z niekontrolowaną alokacją pamięci w Progress Software MOVEit Automation umożliwia nadmiern...
CVE-2026-8486MEDIUM5.3same product
Luka w alokacji zasobów bez limitów lub throttlingu w Progress Software MOVEit Automation umożliwia atak typu ...
CVE-2026-8488MEDIUM4.3same product
Podatność polegająca na przydzielaniu zasobów bez limitów lub throttlingu w Progress Software MOVEit Automatio...