Junglewise Threat Intelligence

CVE-2026-8488: Progress Software MOVEit Automation resource exhaustion in Server

CVE-2026-8488 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Technologies: Progress Software MOVEit Automation. Vendors: Progress Software.

Executive brief

Progress Software MOVEit Automation is a managed file transfer solution used to automate complex data workflows. A vulnerability in the way the system handles resource allocation allows an authenticated user to trigger excessive resource consumption. This can lead to a partial denial of service, potentially slowing down or disrupting automated file transfer operations.

Technical details

An allocation of resources without limits or throttling vulnerability (CWE-770) exists in Progress Software MOVEit Automation. The flaw allows an authenticated attacker with network access to trigger excessive resource allocation within the server component. This is a low-complexity attack that impacts the availability of the service but does not compromise data confidentiality or integrity. The issue is resolved in MOVEit Automation versions 2025.0.11, 2025.1.7, and the 2026 release.

Affected products

  • Progress Software MOVEit Automation before 2025.0.11, 2025.1.0 before 2025.1.7

Timeline

  • 2026-05-18: patched: Fixes included in 2026 release notes
  • 2026-05-20: advisory: NVD publication date

References

Related threats