Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
Two security weaknesses in MOVEit Automation, including a serious bug that might lead to an authentication bypass, have been fixed by Progress Software.
A safe, server-based managed file transfer (MFT) solution called MOVEit Automation (previously Central) is used to plan and automate file movement processes in business settings without the need for bespoke scripts.
The vulnerabilities in question are CVE-2026-5174 (CVSS score: 7.7), an incorrect input validation vulnerability that may permit privilege escalation, and CVE-2026-4670 (CVSS score: 9.8), an authentication bypass vulnerability.
According to an advisory from Progress Software, critical and high vulnerabilities in MOVEit Automation may enable privilege escalation and authentication bypass via the service backend command...

