Junglewise Threat Intelligence

CVE-2026-15967: Progress MOVEit Transfer insufficient session expiration in REST API

CVE-2026-15967 · Severity: high · CVSS 7.5 · Published 2026-07-23

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share sensitive data, contains a vulnerability in how it manages user sessions. An attacker could potentially exploit this flaw to maintain unauthorized access to an account even after security policies should have terminated the session. This could lead to unauthorized data access, modification of files, or disruption of secure transfer operations.

Technical details

An insufficient session expiration vulnerability (CWE-613) exists in the Progress MOVEit Transfer REST API. The flaw stems from improper token refresh checks that fail to adequately enforce current account access policies during session renewal. A remote attacker could potentially exploit this to extend the life of a session beyond its intended expiration or bypass updated access restrictions. Exploitation requires a high degree of complexity and user interaction (UI:R), but successful exploitation grants full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) within the context of the affected user. The issue is addressed in versions 2025.1.5 and 2026.0.3.

Affected products

  • Progress MOVEit Transfer before 2025.1.5, 2026.0.0 before 2026.0.3

Timeline

  • 2026-07-22: patched: Release of MOVEit Transfer 2026.0.3 Service Pack
  • 2026-07-23: disclosed: CVE published to NVD

References

Related threats