CVE-2026-8485 PUBLISHED

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation

Assigner: ProgressSoftware
Reserved: 13.05.2026 Published: 20.05.2026 Updated: 20.05.2026

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.

This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 5.9

Product Status

Vendor Progress Software
Product MOVEit Automation
Versions Default: unaffected
  • affected from 0 to 2025.0.11 (excl.)
  • affected from 2025.1.0 to 2025.1.7 (excl.)

Credits

  • Airbus SecLab finder
  • Anaïs Gantet finder
  • Delphine Gourdou finder
  • Quentin Liddell finder
  • Matteo Ricordeau finder

References

Problem Types

  • CWE-789 Uncontrolled Memory Allocation CWE

Impacts

  • CAPEC-130 Excessive Allocation