CVE-2026-8650: Authenticated Path Traversal allows MOVEit admins to view arbitrary system files
Published Jul 8, 2026
·Updated
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Affected Software
3 affected components
Progress MOVEit Transfer<2025.0.7, >2025.1.0<2025.1.3
Progress MOVEit Transfer<2025.0.7
Progress MOVEit Transfer>=2025.1.1<2025.1.3
Event History
Jul 8, 2026
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Dec 11, 58492
Event
via FIRST·07:26 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-8650?
The severity of CVE-2026-8650 is classified as high with a score of 7.5.
2
How do I fix CVE-2026-8650?
To fix CVE-2026-8650, update your Progress MOVEit Transfer software to version 2025.1.3 or higher.
3
What type of vulnerability is CVE-2026-8650?
CVE-2026-8650 is a relative path traversal vulnerability.
4
Which version of Progress MOVEit Transfer is affected by CVE-2026-8650?
CVE-2026-8650 affects Progress MOVEit Transfer versions before 2025.0.7 and from 2025.1.0 to before 2025.1.3.
5
Can CVE-2026-8650 be exploited remotely?
Yes, CVE-2026-8650 can be exploited by authenticated administrators to view arbitrary system files.