CVE-2026-5174: Improper Access Control Vulnerability in Progress MOVEit Automation
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.
This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5174?
CVE-2026-5174 has been classified as a critical severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2026-5174?
To remediate CVE-2026-5174, users should upgrade Progress MOVEit Automation to versions 2025.1.5 or 2025.0.9 or later.
What systems are affected by CVE-2026-5174?
CVE-2026-5174 affects Progress Software MOVEit Automation versions before 2025.1.5, 2025.0.9, and 2024.1.8.
What causes CVE-2026-5174?
CVE-2026-5174 is caused by an improper access control vulnerability resulting from inadequate input validation.
Can CVE-2026-5174 lead to data breaches?
Yes, CVE-2026-5174 can potentially allow attackers to escalate privileges, which could lead to unauthorized access and data breaches.