Executive brief
Progress MOVEit Transfer is a secure managed file transfer solution used by organizations to share sensitive data. A vulnerability in the administrative settings module could allow an authorized administrator to access files on the underlying system that they should not be able to see. This could lead to the exposure of sensitive configuration files or system data, potentially compromising the security of the server.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the Admin Settings module of Progress MOVEit Transfer. The flaw stems from insufficient validation of user-supplied paths, allowing an attacker with high-level administrative privileges (PR:H) to navigate outside of the intended directory structure. By exploiting this, an authenticated administrator can read arbitrary files on the host operating system. The attack vector is restricted to the adjacent network (AV:A). The issue has been addressed in MOVEit Transfer versions 2025.0.7 and 2025.1.3.
Affected products
- Progress MOVEit Transfer before 2025.0.7, 2025.1.0 before 2025.1.3
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory