CVE-2026-8485
Analyzed
Analyzed - Analysis Complete
Uncontrolled Memory Allocation in Progress MOVEit Automation
Publication date: 2026-05-20
Last updated on: 2026-05-20
Assigner: Progress Software Corporation
Description
Description
Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| progress | moveit_automation | to 2025.0.11 (exc) |
| progress | moveit_automation | From 2025.1.0 (inc) to 2025.1.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-789 | The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated. |