CVE-2026-5174 PUBLISHED

Improper Access Control Vulnerability in Progress MOVEit Automation

Assigner: ProgressSoftware
Reserved: 30.03.2026 Published: 30.04.2026 Updated: 01.05.2026

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.

This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Score: 7.7

Product Status

Vendor Progress Software
Product MOVEit Automation
Versions Default: unaffected
  • affected from 2025.1.0 to 2025.1.5 (excl.)
  • affected from 2025.0.0 to 2025.0.9 (excl.)
  • affected from 2024.0.0 to 2024.1.8 (excl.)
  • affected from 0 to 2024.0.0 (excl.)

Credits

  • Airbus SecLab finder
  • Anaïs Gantet finder
  • Delphine Gourdou finder
  • Quentin Liddell finder
  • Matteo Ricordeau finder

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-233 Privilege Escalation