CVE DATABASE / CVE-2026-5174
CVE-2026-5174
CVSS 7.7 · HIGH
Summary
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
CVSS 3.1 breakdown
| Base score | 7.7 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | CHANGED |
| Confidentiality | NONE |
| Integrity | NONE |
| Availability | HIGH |
Weakness type (CWE)
Affected products
Progress moveit automation
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
Our coverage
References
Data: NIST NVD. NVD last modified 2026-05-04. Always verify against the vendor advisory before acting.