CVE-2026-4670: Improper Authentication vulnerability in Progress MOVEit Automation
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4670?
CVE-2026-4670 is classified as a critical vulnerability due to its authentication bypass capability.
How do I fix CVE-2026-4670?
To fix CVE-2026-4670, upgrade MOVEit Automation to version 2025.0.9 or 2024.1.8 and subsequent releases.
Which versions of MOVEit Automation are affected by CVE-2026-4670?
CVE-2026-4670 affects MOVEit Automation versions prior to 2025.0.9 and prior to 2024.1.8.
What type of vulnerability is CVE-2026-4670?
CVE-2026-4670 is an improper authentication vulnerability that allows for authentication bypass.
Who is affected by CVE-2026-4670?
Any users or organizations utilizing affected versions of Progress Software MOVEit Automation are at risk from CVE-2026-4670.