CVE-2025-11235
Unknown
Unknown - Not Provided
Unverified Password Change Vulnerability in MOVEit Transfer REST API
Publication date: 2026-01-07
Last updated on: 2026-02-03
Assigner: Progress Software Corporation
Description
Description
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| progress | moveit_transfer | From 2023.1.0 (inc) to 2023.1.3 (exc) |
| progress | moveit_transfer | From 2023.0.0 (inc) to 2023.0.8 (exc) |
| progress | moveit_transfer | From 2022.1.0 (inc) to 2022.1.11 (exc) |
| progress | moveit_transfer | From 2022.0.0 (inc) to 2022.0.10 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-620 | When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication. |