Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
References
| Link | Resource |
|---|---|
| https://docs.progress.com/bundle/moveit-transfer-release-notes-2026/page/Fixed-Issues-in-2026.html | Vendor Advisory Release Notes |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-07-08 20:17
Updated : 2026-07-10 19:34
NVD link : CVE-2026-8649
Mitre link : CVE-2026-8649
CVE.ORG link : CVE-2026-8649
JSON object : View
Products Affected
progress
- moveit_transfer
CWE
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
