mediumOther

Progress MOVEit Transfer Custom Reports Query Injection (CVE-2026-8649)

First seen Jul 11, 2026 · Updated Jul 11, 2026 · CVSS 6.4

moveitfile-transferinjectiondata-exposuremanaged-file-transfer

A vulnerability in Progress MOVEit Transfer's Custom Reports module allows improper neutralization of special elements in data query logic, potentially enabling unauthorized data access or manipulation. This affects versions before 2025.0.7 and 2025.1.0 through 2025.1.3, and is reminiscent of prior MOVEit vulnerabilities that were exploited at scale for mass data theft.

Technical Analysis

CVE-2026-8649 stems from improper neutralization of special elements (indicative of an injection-class flaw, likely SQL or query-language injection) within the Custom Reports data query logic of MOVEit Transfer. An authenticated or low-privileged user able to interact with the Custom Reports feature could craft malicious input to manipulate underlying queries, potentially exposing sensitive stored data, session tokens, or credentials. MOVEit Transfer has a well-documented history of being targeted (e.g., CVE-2023-34362) for mass exploitation and data exfiltration campaigns, making this vulnerability class high-interest for threat actors despite the moderate CVSS score of 6.4. Organizations using MOVEit Transfer to move files that feed RAG pipelines, agent tool ingestion, or automated data processing workflows should treat any credential or data exposure from this flaw as a potential source of compromised API keys or documents ingested by downstream AI agents, warranting immediate patching and audit of any agent-facing data flows tied to MOVEit-hosted files.

Affected Systems

Progress MOVEit Transfer versions before 2025.0.7; versions 2025.1.0 through before 2025.1.3 (Custom Reports module specifically)

Indicators of Compromise

  • No specific IOCs published at this time; monitor vendor advisories and NVD/CISA KEV for updates

Remediation Steps

  1. 1

    Patch MOVEit Transfer

    Upgrade to MOVEit Transfer 2025.0.7 or 2025.1.3 (or later) as soon as patches are validated in a test environment.

  2. 2

    Restrict Custom Reports Access

    Limit access to the Custom Reports module to trusted, authenticated administrators only until patching is complete.

  3. 3

    Audit Query Logs

    Review Custom Reports query logs and database access logs for anomalous or malformed query patterns indicative of injection attempts.

  4. 4

    Rotate Credentials

    Rotate any API keys, service account credentials, or tokens stored or transmitted via MOVEit Transfer, particularly those used by automated or AI agent pipelines.

  5. 5

    Monitor for Exploitation

    Subscribe to Progress Software security advisories and CISA KEV updates for indicators of active exploitation of this CVE.

CVE / Advisory IDs

CVE-2026-8649

Industries Most Exposed

financial serviceshealthcaregovernmentlegaleducationmanaged file transfer providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.