Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
References
| Link | Resource |
|---|---|
| https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html | Vendor Advisory Release Notes |
Configurations
Configuration 1 (hide)
|
History
10 Jul 2026, 19:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html - Vendor Advisory, Release Notes | |
| CPE | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* | |
| First Time |
Progress
Progress moveit Transfer |
08 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-08 20:17
Updated : 2026-07-10 19:34
NVD link : CVE-2026-8649
Mitre link : CVE-2026-8649
CVE.ORG link : CVE-2026-8649
JSON object : View
Products Affected
progress
- moveit_transfer
CWE
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
