Executive brief
Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share sensitive data, contains a vulnerability in its Custom Reports module. An attacker with high-level administrative privileges could manipulate data queries to gain unauthorized access to information or interfere with the system's database. This could lead to the exposure of sensitive customer files or disruption of file transfer operations.
Technical details
A vulnerability classified as Improper Neutralization of Special Elements in Data Query Logic (CWE-943) exists in the Custom Reports modules of Progress MOVEit Transfer. The flaw allows an authenticated attacker with high privileges to submit specially crafted input that is not properly sanitized before being used in database queries. This can lead to unauthorized data retrieval, modification, or deletion within the underlying database. The attack is network-reachable but requires high-level administrative permissions to execute. Patches have been released for affected versions 2025.0.x, 2025.1.x, and 2026.0.x.
Affected products
- Progress MOVEit Transfer 2025.0.0 before 2025.0.8, 2025.1.0 before 2025.1.4, 2026.0.0 before 2026.0.1
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory