Skip to content
Progress SoftwareCVE-2026-8649

Improper Neutralization of Special Elements in Data Query Logic vulnerability...

Medium6.4CVE-2026-8649 · Published Jul 8, 2026 · updated Jul 10, 2026

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Progress Software advisory

Affected versions

PackageAffectedFixed in
MOVEit Transfer
Product
>= 2025.1.0, < 2025.1.32025.1.3
< 2025.0.72025.0.7
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-943

More Progress Software advisories

All Progress Software
Advisory
Path equivalence: vulnerability in Progress MOVEit Transfer
Low3.5Jul 8
Progress Software MOVEit Transfer: path traversal
Medium4.5Jul 8
Progress Software MOVEit Transfer: authentication bypass
Low3.7Jul 8
Progress Software MOVEit Transfer: improper authorization
Low2.7Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
High7.2Jul 8
Progress Software MOVEit Transfer: memory leak
High7.5Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.