Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:progress:moveit_transfer:*:*:*:*:*:*:*:* |
Wed, 07 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Progress Progress moveit Transfer |
|
| Vendors & Products |
Microsoft
Microsoft windows Progress Progress moveit Transfer |
Tue, 06 Jan 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10. | |
| Title | MOVEit Transfer REST API does not require current password in order to initiate the password change process | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-01-07T16:25:41.732Z
Reserved: 2025-10-01T19:09:58.385Z
Link: CVE-2025-11235
Updated: 2026-01-07T16:25:19.911Z
Status : Analyzed
Published: 2026-01-07T12:16:46.237
Modified: 2026-02-03T16:54:25.340
Link: CVE-2025-11235
No data.
OpenCVE Enrichment
Updated: 2026-01-07T10:08:17Z