Vulnerability Details CVE-2026-8487
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data.
This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.7%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-8487
-
cpe:2.3:a:progress:moveit_automation:-
-
cpe:2.3:a:progress:moveit_automation:2018.0
-
cpe:2.3:a:progress:moveit_automation:2018.0.3
-
cpe:2.3:a:progress:moveit_automation:2018.2
-
cpe:2.3:a:progress:moveit_automation:2018.2.3
-
cpe:2.3:a:progress:moveit_automation:2018.3
-
cpe:2.3:a:progress:moveit_automation:2018.3.7
-
cpe:2.3:a:progress:moveit_automation:2019.0
-
cpe:2.3:a:progress:moveit_automation:2019.0.3
-
cpe:2.3:a:progress:moveit_automation:2019.1
-
cpe:2.3:a:progress:moveit_automation:2019.1.2
-
cpe:2.3:a:progress:moveit_automation:2019.2
-
cpe:2.3:a:progress:moveit_automation:2019.2.2
-
cpe:2.3:a:progress:moveit_automation:2024.0.0
-
cpe:2.3:a:progress:moveit_automation:2024.1.8
-
cpe:2.3:a:progress:moveit_automation:2025.0.0
-
cpe:2.3:a:progress:moveit_automation:2025.0.1
-
cpe:2.3:a:progress:moveit_automation:2025.0.10
-
cpe:2.3:a:progress:moveit_automation:2025.0.2
-
cpe:2.3:a:progress:moveit_automation:2025.0.3
-
cpe:2.3:a:progress:moveit_automation:2025.0.4
-
cpe:2.3:a:progress:moveit_automation:2025.0.5
-
cpe:2.3:a:progress:moveit_automation:2025.0.6
-
cpe:2.3:a:progress:moveit_automation:2025.0.7
-
cpe:2.3:a:progress:moveit_automation:2025.0.8
-
cpe:2.3:a:progress:moveit_automation:2025.0.9
-
cpe:2.3:a:progress:moveit_automation:2025.1.0
-
cpe:2.3:a:progress:moveit_automation:2025.1.1
-
cpe:2.3:a:progress:moveit_automation:2025.1.2
-
cpe:2.3:a:progress:moveit_automation:2025.1.3
-
cpe:2.3:a:progress:moveit_automation:2025.1.4
-
cpe:2.3:a:progress:moveit_automation:2025.1.5
-
cpe:2.3:a:progress:moveit_automation:2025.1.6