Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174)
Progress MOVEit Automation Critical Pre-Auth Bypass and (TL-2026-0452), also tracked as MOVEit Automation April 2026 Bulletin, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-05-04. It has no confirmed attribution, affects Progress Software MOVEit Automation, references 2 CVEs (CVE-2026-4670, CVE-2026-5174), maps to 26 MITRE ATT&CK techniques (T1003, T1021.002, T1041), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-0452
- Threat ID
- TL-2026-0452
- Also known as
- MOVEit Automation April 2026 Bulletin, Airbus SecLab MOVEit Automation Bypass
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- 2026-05-04
- Last reviewed
- 2026-05-04
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, state-and-local-government, financial-services, healthcare, manufacturing, energy, education, technology, legal, logistics
- Target regions
- North America, Europe, Asia-Pacific, Latin America, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Progress Software disclosed two vulnerabilities in MOVEit Automation, the enterprise managed-file-transfer orchestrator. CVE-2026-4670 (CVSS 9.8, CWE-305) is a critical pre-authentication bypass exploitable remotely without privileges or user interaction; CVE-2026-5174 (CVSS 7.7, CWE-20) is a high-severity privilege escalation in the same backend command-port service. Researchers at Airbus SecLab reported both flaws; over 1,400 MOVEit Automation instances are exposed online (Shodan), including more than a dozen tied to U.S. state and local government agencies.
How Progress MOVEit Automation Critical Pre-Auth Bypass and works
On 30 April 2026 Progress Software published a critical security alert bulletin for MOVEit Automation, the workflow-and-scheduling component of the MOVEit managed-file-transfer (MFT) suite used by approximately 3,000 enterprises and 100,000 administrators worldwide. The bulletin describes two distinct vulnerabilities in the service backend command-port interfaces of MOVEit Automation, both reported to Progress by researchers at Airbus SecLab.
CVE-2026-4670 is an authentication bypass by primary weakness (CWE-305) carrying a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw allows a remote, unauthenticated attacker to reach the backend command-port interface and bypass authentication entirely, gaining administrative control of the MOVEit Automation engine. From that position an attacker can read, modify, or schedule any automation task — including jobs that move sensitive files between SFTP/FTPS/AS2 endpoints, S3/Azure/GCS buckets, and on-prem shares — and can pivot into the host operating system through MOVEit''s task and script execution facilities. The attack requires no user interaction, no privileges, and exhibits low complexity, placing this vulnerability in the highest pre-auth risk tier.
CVE-2026-5174 is an improper input validation flaw (CWE-20) in the same backend command-port surface, carrying a CVSS 3.1 base score of 7.7 (HIGH). The vector is consistent with AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H — network-reachable, low complexity, low-privileged authenticated attacker, scope change, high availability impact — and enables an authenticated actor to escalate privileges or disrupt the automation engine. The two vulnerabilities chain naturally: an attacker who has bypassed authentication via CVE-2026-4670 can leverage CVE-2026-5174 to elevate beyond the access level granted by the bypass and to disrupt automated workflows.
Progress has issued patched releases for every supported branch — 2025.1.5, 2025.0.9, and 2024.1.8 — and stresses that upgrading via the full installer is the only remediation; there is no in-product workaround or hotfix. Versions earlier than 2024.0.0 are end-of-life and remain vulnerable. As of disclosure, no exploitation in the wild has been confirmed by Progress, NVD, or CISA KEV; however, Shodan telemetry shows more than 1,400 internet-exposed MOVEit Automation instances, including over a dozen belonging to U.S. state and local government agencies.
The threat profile is amplified by historical context. In May–June 2023, the CL0P ransomware group exploited a SQL injection zero-day (CVE-2023-34362) in the related product MOVEit Transfer, ultimately compromising more than 2,100 organisations and exposing data on roughly 62 million individuals. CL0P and adjacent extortion crews have since maintained an operational interest in MFT platforms (Cleo, GoAnywhere, MOVEit Transfer) as high-yield ingress points. Although MOVEit Automation differs from MOVEit Transfer in role and codebase, the brand association, the orchestration-level access on offer, and the large exposed surface make CVE-2026-4670 a top-tier candidate for opportunistic mass exploitation by ransomware affiliates and initial-access brokers in the days and weeks following disclosure.
Defenders should patch immediately, restrict MOVEit Automation administrative interfaces to private networks or VPN-fronted access, audit recent automation-task and script-execution history, rotate any credentials stored in MOVEit task definitions, and enable detailed logging on the backend command-port service. CISA''s 2023 MOVEit Transfer playbook (KEV-listed CVE-2023-34362) remains a relevant reference for incident-response posture against this product family.
MITRE ATT&CK techniques used in TL-2026-0452
Credential Access
T1003 OS Credential Dumping; T1552.001 Unsecured Credentials: Credentials In Files
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1098 Account Manipulation; T1505.003 Server Software Component: Web Shell
Execution
T1059 Command and Scripting Interpreter; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Collection
T1074.001 Data Staged: Local Data Staging; T1213 Data from Information Repositories
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Resource Development
Reconnaissance
T1592.002 Gather Victim Host Information: Software; T1595 Active Scanning; T1595.002 Active Scanning: Vulnerability Scanning
defense-impairment
Affected products and versions in Progress MOVEit Automation Critical Pre-Auth Bypass and
- Progress Software — MOVEit Automation
Vulnerable versions: All versions earlier than 2024.0.0 (end-of-life); 2024.0.0 through 2024.1.7; 2025.0.0 through 2025.0.8; 2025.1.0 through 2025.1.4
Fixed in: 2024.1.8; 2025.0.9; 2025.1.5
Remediation for Progress MOVEit Automation Critical Pre-Auth Bypass and
Patches
- MOVEit Automation 2025.1.5 (fixes the 2025.1.x branch)
- MOVEit Automation 2025.0.9 (fixes the 2025.0.x branch)
- MOVEit Automation 2024.1.8 (fixes the 2024.x branch)
- Versions older than 2024.0.0 are end-of-life and must be upgraded to a supported, fixed branch
Immediate actions
- Upgrade MOVEit Automation immediately to a fixed branch: 2025.1.5, 2025.0.9, or 2024.1.8 — full installer is the only supported remediation
- Remove MOVEit Automation administrative and command-port interfaces from direct internet exposure; restrict to management VLAN or VPN-fronted access
- Block inbound access to the MOVEit Automation backend command port at perimeter and host firewalls until patching is confirmed
- Rotate every credential stored in MOVEit Automation task definitions, connection profiles, and saved scripts (SFTP, FTPS, AS2, S3/Azure/GCS, SMB, database)
- Audit MOVEit Automation task history, script-execution logs, and scheduler changes for the trailing 90 days for unauthorised additions or modifications
Workarounds
- No vendor-supplied workaround exists; full-installer upgrade is the only remediation per Progress
- Compensating control: place the MOVEit Automation host behind a VPN/zero-trust gateway and restrict inbound access to known administrator source IPs until patched
Longer-term hardening
- Place MOVEit Automation behind a reverse proxy or WAF with strict allowlists and authenticated-only access
- Deploy EDR on MOVEit Automation hosts with detections for suspicious child processes spawned by the MOVEit Automation service
- Segment MFT infrastructure from general corporate network; treat MFT hosts as Tier 1 / crown-jewel assets
- Subscribe to the Progress Trust Center and Progress security RSS for proactive notification of future advisories
- Establish a documented MFT patch SLA of less than 72 hours for CRITICAL advisories given the historical CL0P targeting pattern
CVEs associated with Progress MOVEit Automation Critical Pre-Auth Bypass and
Weaknesses (CWE) in Progress MOVEit Automation Critical Pre-Auth Bypass and
CWE-305, CWE-20
Timeline of Progress MOVEit Automation Critical Pre-Auth Bypass and
- CL0P ransomware group exploits CVE-2023-34362 zero-day in Progress MOVEit Transfer (sister product), beginning a campaign that ultimately compromises 2,100+ organisations and exposes data on roughly 62 million individuals — establishing the MOVEit product family as a high-value MFT target.
- Researchers at Airbus SecLab identify the authentication-bypass and privilege-escalation flaws in the MOVEit Automation backend command-port interfaces and report them privately to Progress Software (approximate window prior to coordinated disclosure).
- NVD publishes CVE-2026-4670 and CVE-2026-5174 entries crediting Airbus SecLab, with full CVSS 3.1 vectors and affected-version metadata.
- Progress Software publishes the MOVEit Automation Critical Security Alert Bulletin (April 2026) covering CVE-2026-4670 (CVSS 9.8, CWE-305) and CVE-2026-5174 (CVSS 7.7, CWE-20); fixed releases 2025.1.5, 2025.0.9, and 2024.1.8 are made available.
- Threadlinqs Intelligence opens TL-2026-0452 to track CVE-2026-4670 / CVE-2026-5174, prioritising it for monitoring given mass-exposure surface and historical CL0P interest in the MOVEit product family.
- BleepingComputer, GBHackers, and CybersecurityNews publish coverage; Shodan telemetry showing 1,400+ internet-exposed MOVEit Automation instances — including over a dozen tied to U.S. state and local government agencies — drives broader defender awareness.
- As of 2026-05-29, MOVEit Automation CVE-2026-4670/CVE-2026-5174 remain patched (fixes 2024.1.8/2025.0.9/2025.1.5) with no confirmed in-the-wild exploitation, no public PoC, and absent from CISA KEV (catalog 2026.05.29). 1,400+ exposed instances and Cl0p's history of weaponizing MOVEit flaws warrant continued monitoring for resurgence.
Sources cited for Progress MOVEit Automation Critical Pre-Auth Bypass and
- Progress MOVEit Automation Critical Security Alert Bulletin (April 2026) — CVE-2026-4670, CVE-2026-5174
- NVD — CVE-2026-4670
- NVD — CVE-2026-5174
- BleepingComputer — Progress warns of critical MOVEit Automation auth bypass flaw
- GBHackers — MOVEit Authentication Bypass Vulnerability Sparks Security Concerns
- CybersecurityNews — Critical MOVEit Vulnerabilities Enable Authentication Bypass
- OffSeq Threat Radar — CVE-2026-4670 (CWE-305 Authentication Bypass)
- OffSeq Threat Radar — CVE-2026-5174 (CWE-20 Improper Input Validation)
- CISA KEV — CVE-2023-34362 Progress MOVEit Transfer SQL Injection (historical CL0P targeting context)
Threats related to Progress MOVEit Automation Critical Pre-Auth Bypass and
Detection coverage for TL-2026-0452
As of 2026-05-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0452 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.