Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
History

Thu, 30 Apr 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
Description Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Title Improper Access Control Vulnerability in Progress MOVEit Automation
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-04-30T16:08:10.173Z

Reserved: 2026-03-30T17:29:05.971Z

Link: CVE-2026-5174

cve-icon Vulnrichment

Updated: 2026-04-30T16:08:05.188Z

cve-icon NVD

Status : Received

Published: 2026-04-30T16:16:44.330

Modified: 2026-04-30T16:16:44.330

Link: CVE-2026-5174

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.