CVE-2026-8801CWE-46
File Extension Restriction Bypass in MOVEit Transfer
Low · published July 8, 2026
What it is
Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules).
This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
The record
Technical detail
- CVSS v3.1
- 3.5 · LOW
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00345 · 27.4th percentile
- Weakness
- CWE-46 · Path Equivalence: 'filename ' (Trailing Space)
- Published
- 2026-07-08T19:56Z
EPSS history
Timeline