Executive brief
Progress Software MOVEit Automation is a managed file transfer solution used to automate complex workflows and data movement. A vulnerability in how the system handles memory allocation could allow an attacker to cause the service to crash or become unresponsive. This could lead to a disruption in automated business processes and file transfers, though it does not directly expose sensitive data.
Technical details
An uncontrolled memory allocation vulnerability (CWE-789) exists in Progress Software MOVEit Automation. The flaw allows for excessive memory allocation, which can be triggered by a remote attacker. While the attack vector is network-based and requires no authentication, the complexity is rated as high, suggesting specific conditions or configurations must be met to trigger the exhaustion. Successful exploitation results in a denial-of-service (DoS) condition by exhausting available system memory. The issue is addressed in MOVEit Automation versions 2025.0.11, 2025.1.7, and the 2026 release.
Affected products
- Progress Software MOVEit Automation before 2025.0.11, 2025.1.0 before 2025.1.7
Timeline
- 2026-05-20: advisory: NVD publication date
- 2026-05-18: patched: Release notes published for fixed versions