5 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-4670 is a critical authentication bypass vulnerability in Progress MOVEit Automation caused by improper enforcement of authentication mechanisms.
An unauthenticated attacker can exploit this vulnerability over the network by sending crafted requests to the affected system. Successful exploitation may allow unauthorized access to the application without valid credentials, potentially exposing file transfer workflows and sensitive data.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Authentication Bypass Vulnerability in Progress MOVEit Automation
Identifier: CVE-2026-4670
CVSS Score: 9.8 (Critical, CVSS v3.1)
PoC or Exploitation:
Update/ Patch:
- MOVEit Automation versions prior to 2024.0.0
- MOVEit Automation 2024.x versions before 2024.1.8
- MOVEit Automation 2025.0.x versions before 2025.0.9
- MOVEit Automation 2025.1.4 (17.1.4) and earlier
- MOVEit Automation 2024.1.8
- MOVEit Automation 2025.0.9
- MOVEit Automation 2025.1.5 (17.1.5)
Mitigation Recommendation: