Skip to content
CVSS 7.7 · HIGH

CVE-2026-5174

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

View on NVD

Analysis

Progress MOVEit is a high-profile managed file transfer solution with a history of being targeted by major threat actors. A high-severity privilege escalation bug in this product represents a significant risk to enterprise data workflows and internal security architectures.

Severity

Score: 7.7(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: NONE
I: NONE
A: HIGH
Weakness (CWE): CWE-20

EPSS

Probability of exploitation (next 30 days): 0.0010 (0.1%)
Percentile: 27.1%
EPSS: 2026-05-06

Affects

progress:moveit_automation

Technical description

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Published: 4/30/2026, 4:16:44 PM
Last modified: 5/4/2026, 4:47:30 PM

References

HomeEventsBlogResourcesTeam