Junglewise Threat Intelligence

CVE-2026-8800: Progress MOVEit Transfer incorrect authorization in Audit User module

CVE-2026-8800 · Severity: low · CVSS 2.7 · Published 2026-07-08

Technologies: Progress MOVEit Transfer. Vendors: Progress.

Executive brief

Progress MOVEit Transfer, a secure managed file transfer solution, contains a vulnerability in its Audit User module. This flaw could allow a user with audit-level privileges to view sensitive metadata belonging to other organizations within the same system. While the impact is limited to information disclosure, it represents a breach of the intended isolation between different customer environments.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Audit User module of Progress MOVEit Transfer. The flaw allows an authenticated user with high privileges (Audit User) to bypass organizational boundaries and view external token metadata belonging to other organizations. The attack is reachable over the network but requires high-level administrative/audit permissions to execute. The vulnerability has been addressed in versions 2025.0.7 and 2025.1.3. An attacker can achieve unauthorized read access to sensitive configuration metadata but cannot modify data or disrupt service availability.

Affected products

  • Progress MOVEit Transfer before 2025.0.7, 2025.1.0 before 2025.1.3

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References

Related threats