CVE-2026-11903: Stored XSS in MOVEit Transfer Ad Hoc module
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module).
This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11903?
The severity of CVE-2026-11903 is rated as high, with a CVSS score of 8.
How do I fix CVE-2026-11903?
To fix CVE-2026-11903, update Progress MOVEit Transfer to version 2026.0.1 or later, or 2025.1.4 or later, or 2025.0.8 or later.
What is CVE-2026-11903?
CVE-2026-11903 is a stored cross-site scripting (XSS) vulnerability in the MOVEit Transfer Ad Hoc module due to improper neutralization of input.
What software is affected by CVE-2026-11903?
CVE-2026-11903 affects Progress MOVEit Transfer versions prior to 2026.0.1, 2025.1.4, and 2025.0.8.
What can be the impact of CVE-2026-11903?
The impact of CVE-2026-11903 can lead to unauthorized access and data exposure through stored XSS attacks.