{"id":"CVE-2026-8485","title":"Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.","summary":"Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-789"],"vendor":"progress","product":"moveit_automation","affected":["moveit_automation < 2025.0.11","moveit_automation >= 2025.1.0, < 2025.1.7"],"patched":["moveit_automation 2025.1.7"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8485","references":[{"url":"https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html","label":"security@progress.com"}],"tags":["nvd"],"epss":0.00348,"epssPercentile":0.28319,"ingestedAt":"2026-07-23T12:17:55.078Z","slug":"CVE-2026-8485","body":"## Overview\n\nUncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.\n\n## Affected\n\n- `moveit_automation < 2025.0.11`\n- `moveit_automation >= 2025.1.0, < 2025.1.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `moveit_automation 2025.1.7`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}