Executive brief
Progress Software MOVEit Automation is a tool used by organizations to automate complex file transfer workflows and manage data movement between systems. A security flaw in the software's default permission settings could allow an authenticated user to access sensitive data they are not authorized to see. This could lead to the exposure of confidential business information or credentials stored within the system.
Technical details
An incorrect default permissions vulnerability (CWE-276) exists in Progress Software MOVEit Automation. The flaw allows an attacker with low-privileged network access to retrieve embedded sensitive data due to overly permissive default access controls. The vulnerability affects versions prior to 2025.0.11 and versions in the 2025.1.x branch prior to 2025.1.7. An attacker must be authenticated to the system to exploit this issue. Progress Software has released patches to address this vulnerability in the 2026 release cycle and specific maintenance releases.
Affected products
- Progress Software MOVEit Automation before 2025.0.11, 2025.1.0 before 2025.1.7
Timeline
- 2026-05-20: advisory: NVD publication date
- 2026-05-18: patched: Release notes updated with fix information