CVE-2026-4670
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@progress.com — https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| progress | moveit_automation | {"endExcluding":"2024.1.8"} | 2024.1.8 |
References
CWEs
CWE-305
Verify integrity in audit chain (admin only). AS-IS.