CVE-2026-10698
published 2026-07-08CVE-2026-10698: Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit…
PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.64%
49.5th percentile
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| progress | moveit_transfer | <= 2024.1.8 | — |
| progress | moveit_transfer | — | — |
| progress | moveit_transfer | >= 2025.0.0 < 2025.0.8 | 2025.0.8 |
| progress | moveit_transfer | >= 2025.1.0 < 2025.1.4 | 2025.1.4 |
| progress | moveit_transfer | >= 2026.0.0 < 2026.0.1 | 2026.0.1 |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Progress MOVEit Transfer up to 2025.0.7/2025.1.3/2026.0.0 Custom Reports neutralization (Nessus ID 325898 / WID-SEC-2026-2262)
vuldb·2026-07-10·CVSS 7.2
CVE-2026-10698 [HIGH] Progress MOVEit Transfer up to 2025.0.7/2025.1.3/2026.0.0 Custom Reports neutralization (Nessus ID 325898 / WID-SEC-2026-2262)
A vulnerability labeled as critical has been found in Progress MOVEit Transfer up to 2025.0.7/2025.1.3/2026.0.0. Impacted is an unknown function of the component Custom Reports Module. Executing a manipulation can lead to improper neutralization.
This vulnerability is handled as CVE-2026-10698. The attack can be executed remotely. There is not any exploit available.
GHSA
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
ghsa_unreviewed·2026-07-08
CVE-2026-10698 [HIGH] CWE-943 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules).
This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.
Red Hat
awx: websocket EventConsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
vendor_redhat·2026-07-22·CVSS 3.3
CVE-2026-16544 [LOW] CWE-862 awx: websocket EventConsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
awx: websocket EventConsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698.
Statement: T
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-08
Published