Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-8801: MOVEit Transfer File Upload Bypass Vulnerability

CVE-2026-8801 CVE-2026-8801
Summary

MOVEit Transfer, a file transfer software, has a security weakness in its file upload module. This vulnerability can allow unauthorized access to the system, potentially leading to data theft or other security breaches. To protect your data, update to MOVEit Transfer version 2025.0.8 or later, or version 2025.1.4 or later if you're using version 2025.1.0.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
progress moveit transfer < 2025.1.4
progress moveit_transfer < 2025.0.8
>= 2025.1.0, < 2025.1.4
cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:*
Original title
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Original description
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).

This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
nvd CVSS3.1 3.5
Vulnerability type
CWE-46
Published: 8 Jul 2026 · Updated: 23 Jul 2026 · First seen: 8 Jul 2026