CVE-2026-8487

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_automation:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_automation:*:*:*:*:*:*:*:*

History

21 May 2026, 18:56

Type Values Removed Values Added
First Time Progress
Progress moveit Automation
References () https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html - () https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html - Release Notes
CPE cpe:2.3:a:progress:moveit_automation:*:*:*:*:*:*:*:*

20 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 16:16

Updated : 2026-05-21 18:56


NVD link : CVE-2026-8487

Mitre link : CVE-2026-8487

CVE.ORG link : CVE-2026-8487


JSON object : View

Products Affected

progress

  • moveit_automation
CWE
CWE-276

Incorrect Default Permissions