CVE-2026-5174
Eine Schwachstelle durch unsachgemäße Eingabevalidierung in Progress Software MOVEit Automation ermöglicht eine Erhöhung von Berechtigung… (CVE-2026-5174)
highEPSS 3.2 %
Beschreibung
Eine Schwachstelle durch unsachgemäße Eingabevalidierung in Progress Software MOVEit Automation ermöglicht eine Erhöhung von Berechtigungen. Dieses Problem betrifft MOVEit Automation: Versionen ab 2025.1.0 bis einschließlich 2025.1.4, ab 2025.0.0 bis einschließlich 2025.0.8, ab 2024.0.0 bis einschließlich 2024.1.7 und alle Versionen vor 2024.0.0.
Metriken
Severity
high
114.81
kein öffentlicher PoC bekannt
7.7
87.6 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
Veröffentlicht
2026-04-30 15:07 UTC
CWE-20
Weakness-Klassen (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
Quellen & Referenzen
Verknüpfte Empfehlungen
IDCVE-2026-5174