CVE-2026-8487
πΆ mediumSummary
Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.
CVSS Score
6.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2026-05-20
First Seen: 2026-05-21
π Relative Risk Intelligence
This CVE is Lower Risk - more severe than 47.8% of all 330,193 vulnerabilities in our database.
#172,448
Below average severity
Severity Percentile
π― CISA SSVC Assessment Updated: May 20, 2026
π Exploitation Status
None
No known exploits
βοΈ Automatable
NO
Requires human interaction
π₯ Technical Impact
Partial
Limited system impact
π Discovered By
Airbus SecLab
AnaΓ―s Gantet
Delphine Gourdou
Quentin Liddell
Matteo Ricordeau
SSVC data provided by
CISA
Last Modified
2026-05-21
Source
NVD π
CVSS Vector 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)