Executive brief
Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share data, contains a security vulnerability in its HTTPS module. An attacker could potentially bypass certain authentication checks by spoofing identity information. While the impact is limited, it could allow unauthorized actions that compromise the integrity of the system's security controls.
Technical details
A vulnerability classified as Authentication Bypass by Spoofing (CWE-290) exists in the HTTPS module of Progress MOVEit Transfer. The flaw stems from improper IP resolution when accessing the machine interface, which could allow a remote attacker to bypass certain authentication or authorization checks by spoofing their identity. The attack complexity is considered high, as it likely requires specific environmental conditions or knowledge of the internal network structure to successfully spoof the expected identity. Progress has released patches in versions 2025.0.7 and 2025.1.3 to address this issue.
Affected products
- Progress MOVEit Transfer before 2025.0.7, 2025.1.0 to 2025.1.3
Timeline
- 2026-07-08: advisory
- 2026-07-08: disclosed