Status: EPSS-IMMINENT | Advisory ID: CVE-2026-4670
| CVE | CVE-2026-4670 |
| CVSS | CVSS 9.8 (Critical). |
| Affected products | Progress moveit_automation |
| Classified as | CWE-305 (Authentication Bypass by Primary Weakness) |
| Exploitation prediction (EPSS) | 6% probability of exploitation in the next 30 days (93% percentile) -- FIRST.org's EPSS model. |
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.