CVE-2026-5174

Eine Schwachstelle durch unsachgemäße Eingabevalidierung in Progress Software MOVEit Automation ermöglicht eine Erhöhung von Berechtigung… (CVE-2026-5174)

Beschreibung

Eine Schwachstelle durch unsachgemäße Eingabevalidierung in Progress Software MOVEit Automation ermöglicht eine Erhöhung von Berechtigungen. Dieses Problem betrifft MOVEit Automation: Versionen ab 2025.1.0 bis einschließlich 2025.1.4, ab 2025.0.0 bis einschließlich 2025.0.8, ab 2024.0.0 bis einschließlich 2024.1.7 und alle Versionen vor 2024.0.0.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.7
Quelle: nvd-v3
87.6 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
3.2 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-04-30 15:07 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-5174