CVE-2026-8801CWE-46

File Extension Restriction Bypass in MOVEit Transfer

Low · published July 8, 2026

CVSS v3.1
3.5
EPSS
0%
Percentile
27.4
In the wild
Unconfirmed
What it is

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).

This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

The record
Technical detail
CVSS v3.1
3.5 · LOW
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00345 · 27.4th percentile
Weakness
CWE-46 · Path Equivalence: 'filename ' (Trailing Space)
Published
2026-07-08T19:56Z
EPSS history
Timeline
  • 08 JUL 19:56Z
    File Extension Restriction Bypass in MOVEit Transfer
    cvelistv5