Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass (Updated)
Progress Software has patched a critical authentication bypass flaw in MOVEit Automation (CVE‑2026‑4670, CVSS 9.8) that allows unauthenticated remote access to the system. Immediate upgrading to the fixed versions is the only remediation.
What the vulnerability is
The primary issue, CVE‑2026‑4670, is an authentication bypass in MOVEit Automation’s backend command port interfaces. An attacker with network access can:
Bypass authentication entirely
Gain unauthorized access
Potentially obtain administrative control
Access or exfiltrate sensitive data
This is a low‑complexity, no‑user‑interaction exploit path.
A second flaw, CVE‑2026‑5174 (CVSS 7.7), allows privilege escalation via improper input validation. Attackers can chain both vulnerabilities for full system compromise.
Affected versions
All MOVEit Automation builds before the following are vulnerable:
2025.1.5
2025.0.9
2024.1.8
Anything older than these versions is exploitable.
Required action (no workarounds exist)
Progress is explicit:
Upgrading to a patched release using the full installer is the only way to remediate this issue. There will be an outage during the upgrade.
There are no mitigations, no configuration changes, and no firewall rules that fully eliminate the risk.
Why this matters
MOVEit Automation is widely deployed in enterprise and government environments, and MFT platforms have a history of being targeted by ransomware groups (e.g., Cl0p’s 2023 MOVEit Transfer mass‑exploitation campaign). While Progress has not yet confirmed in‑the‑wild exploitation, the exposure is significant:
Over 1,400 MOVEit Automation instances are internet‑facing
Several belong to U.S. state and local government agencies
Given the severity and past exploitation patterns, this should be treated as urgent.
Indicators & symptoms
Progress notes that exploitation may manifest as:
Unexpected privilege escalation
Unauthorized access events
Anomalous activity in MOVEit Automation audit logs
Summary table
| Item | Details |
|---|---|
| Primary CVE | CVE‑2026‑4670 (Auth bypass, CVSS 9.8) |
| Secondary CVE | CVE‑2026‑5174 (Privilege escalation, CVSS 7.7) |
| Impact | Unauthorized access, admin control, data exposure |
| Attack complexity | Low; no user interaction |
| Affected versions | <2025.1.5, <2025.0.9, <2024.1.8 |
| Fix | Upgrade to patched versions (full installer required) |
| Workarounds | None |
Next step for you
If you want, I can generate a MOVEit Automation emergency response checklist tailored for your environment (patch validation, log review, network exposure scanning, and post‑upgrade verification).
Comments
Post a Comment