CVE-2026-8800: Cross-Org External Token Metadata accessible to AuditUser role
Published Jul 8, 2026
·Updated
Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module).
This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
Affected Software
3 affected components
Progress MOVEit Transfer<2025.0.7, >2025.1.0<2025.1.3
Progress MOVEit Transfer<2025.0.7
Progress MOVEit Transfer>=2025.1.1<2025.1.3
Event History
Jul 8, 2026
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Dec 31, 58607
Event
via FIRST·04:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8800?
CVE-2026-8800 has a high severity score of 8.8.
2
How do I fix CVE-2026-8800?
To fix CVE-2026-8800, upgrade to Progress MOVEit Transfer version 2025.1.3 or later.
3
What type of vulnerability is CVE-2026-8800?
CVE-2026-8800 is a Cross-Org External Token Metadata accessibility issue due to incorrect authorization.
4
Which versions of Progress MOVEit Transfer are affected by CVE-2026-8800?
CVE-2026-8800 affects Progress MOVEit Transfer versions before 2025.0.7 and from 2025.1.0 before 2025.1.3.
5
What does CVE-2026-8800 affect within Progress MOVEit Transfer?
CVE-2026-8800 affects the Audit User module, allowing improper access to external token metadata.