SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-8649

MEDIUM · CVSS 6.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A vulnerability exists in the Custom Reports module of Progress MOVEit Transfer, where improper neutralization of special elements in data query logic can lead to potential data exposure or manipulation. Organizations using affected versions prior to 2025.0.7 and between 2025.1.0 and 2025.1.3 should prioritize remediation to mitigate risks associated with unauthorized access to sensitive data.

CVE
CVE-2026-8649
Severity
MEDIUM
CVSS
6.4
EPSS
0.26%

Original NVD Description

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)