{"id":"CVE-2026-8487","title":"Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.","summary":"Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-276"],"vendor":"progress","product":"moveit_automation","affected":["moveit_automation < 2025.0.11","moveit_automation >= 2025.1.0, < 2025.1.7"],"patched":["moveit_automation 2025.1.7"],"published":"2026-05-20","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8487","references":[{"url":"https://docs.progress.com/bundle/moveit-automation-release-notes-2026/page/Fixed-Issues-2026.html","label":"security@progress.com"}],"tags":["nvd"],"epss":0.0028,"epssPercentile":0.2067,"ingestedAt":"2026-07-23T12:17:55.237Z","slug":"CVE-2026-8487","body":"## Overview\n\nIncorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data.\n\nThis issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.\n\n## Affected\n\n- `moveit_automation < 2025.0.11`\n- `moveit_automation >= 2025.1.0, < 2025.1.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `moveit_automation 2025.1.7`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}