Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174) — Threadlinqs Intelligence
As of 2026-05-30, Progress MOVEit Automation Critical Pre-Auth Bypass and Privilege Escalation (CVE-2026-4670, CVE-2026-5174) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-0452 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: VULNERABILITY
Progress Software disclosed two vulnerabilities in MOVEit Automation, the enterprise managed-file-transfer orchestrator. CVE-2026-4670 (CVSS 9.8, CWE-305) is a critical pre-authentication bypass
On 30 April 2026 Progress Software published a critical security alert bulletin for MOVEit Automation, the workflow-and-scheduling component of the MOVEit managed-file-transfer (MFT) suite used by approximately 3,000 enterprises and 100,000 administrators worldwide. The bulletin describes two distinct vulnerabilities in the service backend command-port interfaces of MOVEit Automation, both reported to Progress by researchers at Airbus SecLab.
CVE-2026-4670 is an authentication bypass by primary weakness (CWE-305) carrying a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The flaw allows a remote, unauthenticated attacker to reach the backend command-port interface and bypass authentication entirely, gaining administrative control of the MOVEit Automation engine. From that position an attacker can read, modify, or schedule any automation task — including jobs that move sensitive files between SFTP/FTPS/AS2 endpoints, S3/Azure/GCS buckets, and on-prem shares — and can pivot into the host operating system through MOVEit''s task and script execution facilities. The attack requires no user interaction, no privileges, and exhibits low complexity, placing this vulnerability in the highest pre-auth risk tier.
CVE-2026-5174 is an improper input validation flaw (CWE-20) in the same backend command-port surface, carrying a CVSS 3.1 base score of 7.7 (HIGH). The vector is consistent with AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H — network-reachable, low complexity, low-privileged authenticated attacker, scope change, high availability impact — and enables an authenticated actor to escalate privileges or disrupt the automation engine. The two vulnerabilities chain naturally: an attacker who has bypassed authentication via CVE-2026-4670 can leverage CVE-2026-5174 to elevate beyond the access level granted by the bypass and to disrupt automated workflows.
Progress has issued patched releases for every supported branch — 2025.1.5, 2025.0.9, and 2024.1.8 — and stresses that upgrading via the full installer is the only remediation; there is no in-product workaround or hotfix. Versions earlier than 2024.0.0 are end-of-life and remain vulnerable. As of disclosure, no exploitation in the wild has been confirmed by Progress, NVD, or CISA KEV; however, Shodan telemetry shows more than 1,400 internet-exposed MOVEit Automation instances, including over a dozen belonging to U.S. state and local government agencies.
The threat profile is amplified by historical context. In May–June 2023, the CL0P ransomware group exploited a SQL injection zero-day (CVE-2023-34362) in the related product MOVEit Transfer, ultimately compromising more than 2,100 organisations and exposing data on roughly 62 million individuals. CL0P and adjacent extortion crews have since maintained an operational interest in MFT platforms (Cleo, GoAnywhere, MOVEit Transfer) as high-yield ingress points. Although MOVEit Automation differs from MOVEit Transfer in role and codebase, the brand association, the orchestration-level access on offer, and the large exposed surface make CVE-2026-4670 a top-tier candidate for opportunistic mass exploitation by ransomware affiliates and initial-access brokers in the days and weeks following disclosure.
Defenders should patch immediately, restrict MOVEit Automation administrative interfaces to private networks or VPN-fronted access, audit recent automation-task and script-execution history, rotate any credentials stored in MOVEit task definitions, and enable detailed logging on the backend command-port service. CISA''s 2023 MOVEit Transfer playbook (KEV-listed CVE-2023-34362) remains a relevant reference for incident-response posture against this product family.
Weaknesses (CWE)
CWE-305, CWE-20
Target sectors: government, state-and-local-government, financial-services, healthcare, manufacturing, energy, education, technology, legal, logistics
Target regions: North America, Europe, Asia-Pacific, Latin America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-4670, CVE-2026-5174, T1595, T1595.002, T1592.002, T1583, T1190, T1078, T1059, T1059.001, T1059.003, T1505.003