CVE-2026-10697 PUBLISHED

MFA Bypass in MOVEit Transfer

Assigner: ProgressSoftware
Reserved: 02.06.2026 Published: 23.07.2026 Updated: 24.07.2026

Improper Authentication vulnerability in Progress MOVEit Transfer.

This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor Progress
Product MOVEit Transfer
Versions Default: unaffected
  • affected from 0 to 2025.1.5 (excl.)
  • affected from 2026.0.0 to 2026.0.3 (excl.)

Credits

  • Niv Levy finder

References

Problem Types

  • CWE-287: Improper Authentication CWE