CVE-2026-5174

7.7

Progress Software · MOVEit Automation

Progress Software MOVEit Automation is susceptible to an improper input validation vulnerability that enables authenticated users to perform privilege escalation.

Executive summary

A high-severity privilege escalation vulnerability in Progress Software MOVEit Automation, tracked as CVE-2026-5174, poses a significant risk to organizational data integrity and access control.

Vulnerability

This vulnerability arises from improper input validation, allowing an authenticated attacker with low privileges to escalate their access level within the MOVEit Automation environment.

Business impact

Successful exploitation of this flaw allows a malicious actor to gain unauthorized administrative privileges, potentially leading to full system compromise or unauthorized manipulation of automated workflows. Given the CVSS score of 7.7, this vulnerability represents a high risk to business operations, as MOVEit is often used for sensitive data transfers. Failure to remediate could result in unauthorized access to sensitive files or the disruption of critical business processes.

Remediation

Immediate Action: Administrators must review the official Progress Software security bulletin and apply the vendor-provided patches for their specific version of MOVEit Automation.

Proactive Monitoring: Security teams should audit system logs for unusual administrative activity or unauthorized changes to user permission settings.

Compensating Controls: Deploy a Web Application Firewall with rules configured to inspect and filter malicious input patterns targeting the MOVEit application interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Progress Software MOVEit Automation must prioritize this update as part of their routine patch management cycle. Given the potential for privilege escalation, it is imperative to verify that all user roles and permissions are correctly configured following the application of the vendor patch.

More Progress Software CVEs

Sources

Originally found and disclosed by Airbus SecLab, Anaïs Gantet, Delphine Gourdou, Quentin Liddell, Matteo Ricordeau, per the CVE Program record.