Progress MOVEit Transfer Improper Neutralization of Special Elements in Data Query Logic Vulnerability

Vulnerability

A table scope bypass vulnerability has been identified in the Custom Reports module of Progress MOVEit Transfer. This vulnerability affects versions 2025.0.0 prior to 2025.0.8, 2025.1.0 prior to 2025.1.4, and 2026.0.0 prior to 2026.0.1. The issue allows a high-privilege attacker to execute a custom report that could expose API tokens belonging to other MOVEit users in the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access to API tokens of other users, potentially allowing for session hijacking or unauthorized actions on behalf of those users.

Remediation

Users are advised to upgrade to MOVEit Transfer versions 2026.0.1, 2025.1.4, or 2025.0.8. For customers on a current maintenance agreement, the upgrade can be accessed through the Progress Community. Those not on a maintenance agreement should contact a Progress Sales Representative or their respective partner.

Added: Jul 8, 2026, 5:06 PM
Updated: Jul 8, 2026, 5:06 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
5.4
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.