Executive brief
Progress MOVEit Transfer, a managed file transfer solution used by organizations to securely share data, contains a vulnerability in its file upload module. An attacker with basic user permissions could potentially bypass security rules that restrict which types of files are allowed to be uploaded. This could lead to the storage of unauthorized or prohibited file types on the corporate server.
Technical details
A path equivalence vulnerability (CWE-46) exists in the File Upload modules of Progress MOVEit Transfer. The flaw stems from improper handling of filenames, specifically involving trailing spaces or similar path equivalence techniques, which can be used to bypass configured file extension restrictions. An attacker with low-privileged network access and minimal user interaction could exploit this to upload prohibited file types. The issue is resolved in versions 2025.0.8 and 2025.1.4.
Affected products
- Progress MOVEit Transfer before 2025.0.8, 2025.1.0 before 2025.1.4
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory