Junglewise Threat Intelligence

CVE-2026-11903: Progress MOVEit Transfer XSS in Ad Hoc module

CVE-2026-11903 · Severity: high · CVSS 8 · Published 2026-07-08

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer is a managed file transfer solution used by organizations to securely share sensitive data. A security vulnerability in its Ad Hoc module could allow an attacker to execute malicious scripts in a user's browser. If exploited, this could lead to unauthorized access to user sessions, sensitive file data, or the compromise of the application's integrity.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Ad Hoc module of Progress MOVEit Transfer due to improper neutralization of user-supplied input during web page generation. An authenticated attacker with low privileges can inject malicious scripts that are executed when a victim views affected pages within the application. This vulnerability (CWE-79) requires user interaction but can result in high impacts to confidentiality, integrity, and availability by allowing session hijacking or unauthorized actions. The issue is addressed in versions 2026.0.1, 2025.1.4, and 2025.0.8.

Affected products

  • Progress MOVEit Transfer 2026.0.0 before 2026.0.1, 2025.1.0 before 2025.1.4, 2025.0.0 before 2025.0.8

Timeline

  • 2026-07-08: advisory: NVD publication date
  • 2026-06: disclosed: Vendor bulletin month

References

Related threats