CyberRota Analysis
AI-GeneratedA vulnerability exists in the Custom Reports module of Progress MOVEit Transfer, where improper neutralization of special elements in data query logic can lead to potential data exposure or manipulation. Organizations using affected versions prior to 2025.0.7 and between 2025.1.0 and 2025.1.3 should prioritize remediation to mitigate risks associated with unauthorized access to sensitive data.
CVE
CVE-2026-8649
Severity
MEDIUM
CVSS
6.4
EPSS
0.26%
Original NVD Description
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Related CVEs
Other vulnerabilities affecting the same vendor(s)