Skip to content
CVSS 7.7 · HIGH

CVE-2026-5174

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Ver en NVD

Análisis

Progress MOVEit is a high-profile managed file transfer solution with a history of being targeted by major threat actors. A high-severity privilege escalation bug in this product represents a significant risk to enterprise data workflows and internal security architectures.

Severidad

Puntaje: 7.7(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: NONE
I: NONE
A: HIGH
Tipo de falla (CWE): CWE-20

EPSS

Probabilidad de explotación (próx. 30 días): 0.0010 (0.1%)
Percentil: 27.1%
EPSS: 2026-05-06

Afecta

progress:moveit_automation

Descripción técnica

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Publicada: 30/4/2026, 16:16:44
Última modificación: 4/5/2026, 16:47:30

Referencias

InicioEventosBlogRecursosEquipo