Critical MOVEit Automation auth bypass vulnerability fixed (CVE-2026-4670)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34362 | Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known. Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies. | 9.8 | 100% | KEV ransomware PoC |
| large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans) | |
| CVE-2026-4670 +1 in the same advisory: …5174 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. NVD description · AI analysis pending | 9.8 group max | 6% |
| — |
Full article339 words · extracted from helpnetsecurity.com · click to collapse
Progress Software has fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) vulnerability in MOVEit Automation, exploitation of which “may lead to unauthorized access, administrative control, and data exposure.”
The vulnerabilities were reported privately by Airbus researchers and there’s no mention of them being leveraged by attackers in the wild. Still, performing an upgrade to a fixed version is “strongly” advised.
CVE-2026-4670 and CVE-2026-5174
Progress Software’s MOVEit Transfer, an enterprise managed file transfer (MFT) solution, was infamously targeted by the Cl0p cyber extortion outfit in 2023 via CVE-2023-34362, a SQL injection flaw that allowed for remote code execution.
MOVEit Transfer is the secure server used for storing and transferring files, while MOVEit Automation is the workflow/scheduling engine that sits automates those file transfers.
The newly patched CVE-2026-4670 and CVE-2026-5174 affect the service backend command port interface of MOVEit Automation versions 2025.1.4 (17.1.4) and earlier, 2025.0.8 (17.0.8) and earlier, and 2024.1.7 (16.1.7) and earlier.
CVE-2026-4670 is an authentication bypass vulnerability that can be exploited via low-complexity attacks by unauthenticated attackers. CVE-2026-5174, caused by improper input validation, may allow authenticated attackers to escalate their privileges. Together, the two vulnerabilities may allows remote attackers to gain administrative control of MOVEit Automation instances.
This kind of access would allow them access to credentials stored in MOVEit Automation tasks, to sensitive business data (reports, payroll, financial files, etc.), and to the wider enterprise network.
Fortunately, neither the company or the AirBus team released technical details.
Update via installer
The two vulnerabilities have been fixed in MOVEit Automation versions 2025.1.5, 2025.0.9, and 2024.1.8.
“Upgrading to a patched release, using the full installer, is the only way to remediate this issue. There will be an outage to the system while the upgrade is running,” the company noted in the security advisory.
They also added that unexpected privilege escalation, unauthorized access, or anomalous activity observed via the audit logs may point to CVE-2026-4670 exploitation.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/