Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-8649: Progress MOVEit Transfer Custom Reports Exposed to Unauthorized Data Access

CVE-2026-8649 CVE-2026-8649
Summary

Custom reports in Progress MOVEit Transfer can allow unauthorized users to access sensitive data. This affects MOVEit Transfer versions before 2026.0.0, 2025.1.3, and 2025.0.7. To fix this, update to the latest version of MOVEit Transfer.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
progress moveit transfer < 2025.1.3
progress moveit_transfer < 2025.0.7
>= 2025.1.0, < 2025.1.3
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
Original title
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1...
Original description
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).

This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
mitre CVSS3.1 6.4
Vulnerability type
CWE-943
Published: 8 Jul 2026 · Updated: 20 Jul 2026 · First seen: 8 Jul 2026