CVE-2026-8487
MEDIUMIncorrect default permissions vulnerability in Progress Software MOVEit Automation
Title source: cnaDescription
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html
Scores
CVSS v3
6.5
EPSS
0.0011
EPSS Percentile
28.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-276
Status
published
Products (3)
progress/moveit_automation
< 2025.0.11
Progress Software/MOVEit Automation
< 2025.0.11
Progress Software/MOVEit Automation
2025.1.0 - 2025.1.7
Published
May 20, 2026
Tracked Since
May 20, 2026