CVE-2026-8801: File Extension Restriction Bypass in MOVEit Transfer
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).
This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MOVEit Transfer (File Upload modules)to a version that resolves this vulnerability.Fixed in 2025.0.8 - Upgrade
Upgrade
Progress MOVEit Transfer (File Upload modules)to a version that resolves this vulnerability.Fixed in 2025.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8801?
CVE-2026-8801 has a critical severity rating of 9.8.
How do I fix CVE-2026-8801?
To resolve CVE-2026-8801, upgrade Progress MOVEit Transfer to version 2025.1.4 or later.
What systems are affected by CVE-2026-8801?
CVE-2026-8801 affects Progress MOVEit Transfer versions prior to 2025.0.8 and from 2025.1.0 to before 2025.1.4.
What type of vulnerability is CVE-2026-8801?
CVE-2026-8801 is a file extension restriction bypass vulnerability.
When was CVE-2026-8801 published?
CVE-2026-8801 was published on July 8, 2026.