← All Advisories

Improper input validation in Progress MOVEit Automation opens a path to privilege escalation

Status: UPDATED  |  Advisory ID: CVE-2026-5174

Key Details

CVECVE-2026-5174
CVSS Score / Version7.7 (High) / CVSS v3.1
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsProgress moveit_automation
Classified asCWE-20 (Improper Input Validation)
Exploitation prediction (EPSS)3.24% probability of exploitation in the next 30 days (88% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Progressmoveit_automation
SubsystemsGeneral OT
SectorsMultiple

What to Know

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.

This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

What to Do

Monitor Progress's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5174
Vendor advisoryhttps://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174