CVE-2026-15966
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Progress | MOVEit Transfer | 0 < 2025.1.5 | affected |
| Progress | MOVEit Transfer | 2026.0.0 < 2026.0.3 | affected |
Weaknesses
- CWE-942: CWE-942 Permissive cross-domain security policy with untrusted domains
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.