CVE-2026-8651

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

History

09 Jul 2026, 19:18

Type Values Removed Values Added
First Time Progress
Progress moveit Transfer
References () https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html - () https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html - Release Notes
CPE cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*

08 Jul 2026, 20:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 20:17

Updated : 2026-07-09 19:18


NVD link : CVE-2026-8651

Mitre link : CVE-2026-8651

CVE.ORG link : CVE-2026-8651


JSON object : View

Products Affected

progress

  • moveit_transfer
CWE
CWE-290

Authentication Bypass by Spoofing