CVE-2026-8801
Analyzed Analyzed - Analysis Complete

Path Equivalence Vulnerability in Progress MOVEit Transfer

Vulnerability report for CVE-2026-8801, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-09

Assigner: Progress Software Corporation

Description

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-09
Generated
2026-07-15
AI Q&A
2026-07-08
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
progress moveit_transfer to 2025.0.8 (exc)
progress moveit_transfer From 2025.1.0 (inc) to 2025.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-46 The product accepts path input in the form of trailing space ('filedir ') without appropriate validation, which can lead to ambiguous path resolution and allow an attacker to traverse the file system to unintended locations or access arbitrary files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path equivalence issue found in the Progress MOVEit Transfer software, specifically in its File Upload modules. It affects versions before 2025.0.8 and versions from 2025.1.0 before 2025.1.4.

Impact Analysis

The vulnerability has a CVSS base score of 3.5, indicating a low severity. It requires network access with low complexity and privileges, and user interaction is required. The impact is limited to integrity loss without affecting confidentiality or availability.

Compliance Impact

CVE-2026-8801 is a high severity vulnerability (CVSS 9.8) in Progress MOVEit Transfer that involves path equivalence issues in file upload modules, potentially allowing unauthorized access or manipulation of files.

Such unauthorized access or data manipulation could lead to exposure or compromise of sensitive data, which may impact compliance with data protection regulations such as GDPR or HIPAA that require strict controls over data confidentiality, integrity, and access.

However, the provided context and resources do not explicitly describe the direct impact of this vulnerability on compliance with these standards.

Mitigation Strategies

This vulnerability affects MOVEit Transfer versions before 2025.0.8 and from 2025.1.0 before 2025.1.4.

To mitigate this vulnerability, you should upgrade MOVEit Transfer to version 2025.0.8 or later, or if using the 2025.1.x series, upgrade to version 2025.1.4 or later.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8801. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart