Junglewise Threat Intelligence

CVE-2026-15966: Progress MOVEit Transfer permissive cross-domain policy in WebUI

CVE-2026-15966 · Severity: high · CVSS 7.5 · Published 2026-07-23

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a managed file transfer solution used for secure data exchange, contains a security flaw in its web interface. This vulnerability could allow a malicious website to interact with a user's active MOVEit session if the user visits the malicious site while logged in. This could lead to unauthorized access to sensitive files, data modification, or full account takeover.

Technical details

A permissive cross-domain security policy (CWE-942) exists in the Progress MOVEit Transfer WebUI. The application fails to properly restrict which external domains can interact with its resources, potentially allowing untrusted domains to bypass standard browser-based same-origin protections. An attacker could exploit this by enticing an authenticated user to visit a malicious website, which could then perform actions or retrieve data from the MOVEit Transfer instance on the user's behalf. The vulnerability is addressed in versions 2025.1.5 and 2026.0.3 by implementing security hardening to protect authenticated sessions against unintended cross-origin resource sharing.

Affected products

  • Progress MOVEit Transfer before 2025.1.5, 2026.0.0 before 2026.0.3

Timeline

  • 2026-07-22: patched: Fix released in version 2026.0.3
  • 2026-07-23: disclosed: Initial advisory publication

References

Related threats