← All Advisories

CVE-2026-4670

Status: EPSS-IMMINENT  |  Advisory ID: CVE-2026-4670

Key Details

CVECVE-2026-4670
CVSSCVSS 9.8 (Critical).
Affected productsProgress moveit_automation
Classified asCWE-305 (Authentication Bypass by Primary Weakness)
Exploitation prediction (EPSS)6% probability of exploitation in the next 30 days (93% percentile) -- FIRST.org's EPSS model.

What to Know

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.

This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-4670
Vendor advisoryhttps://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174