← Vulnerability feed

Vulnerability record · CVE-2024-5806 · published 25 June 2024

CVE-2024-5806: Progress MOVEit Transfer SFTP authentication bypass

Progress · Moveit Transfer

Progress MOVEit Transfer contains an improper authentication flaw in its SFTP module that allows authentication bypass. The affected versions are 2023.0.0 before 2023.0.11, 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2. Because MOVEit Transfer is widely used for managed file transfers, a bypass of this kind exposes sensitive data flows and is rated critical by NVD.

9.8 CVSS 3.1 Critical EPSS 81% · top 0.4% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or user interaction required, and a very high EPSS score make this a top remediation priority despite no KEV listing.

What it is

Progress MOVEit Transfer contains an improper authentication flaw in its SFTP module that allows authentication bypass. The affected versions are 2023.0.0 before 2023.0.11, 2023.1.0 before 2023.1.6, and 2024.0.0 before 2024.0.2. Because MOVEit Transfer is widely used for managed file transfers, a bypass of this kind exposes sensitive data flows and is rated critical by NVD.

Impact

An attacker can bypass authentication and gain unauthorized access to the SFTP service, with the CVSS vector indicating high confidentiality, integrity, and availability impact. In practice this means access to transferred files and the ability to act within the SFTP context without valid credentials.

Attack surface

The flaw is reachable over the network through the SFTP module, with no privileges or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed MOVEit Transfer SFTP endpoint is in scope.

Exploitation

EPSS is very high (0.81474, 99.6th percentile), indicating elevated likelihood of exploitation activity. The record is not listed in CISA KEV and the references carry only Vendor Advisory and Product tags, so no confirmed in-the-wild exploitation is documented here.

What to do

  • Upgrade MOVEit Transfer to 2023.0.11, 2023.1.6, 2024.0.2 or later as directed by the Progress advisory.
  • If immediate patching is not possible, restrict or disable external access to the SFTP service and limit it to trusted networks.
  • Review Progress guidance for any interim configuration or mitigation steps specific to the SFTP module.
  • Audit SFTP accounts and access logs for unexpected or unauthorized sessions.
  • Apply network segmentation so MOVEit Transfer is not directly reachable from untrusted networks.

Detection

  • Monitor SFTP authentication logs for successful logins that lack a corresponding valid credential or expected source.
  • Alert on anomalous SFTP sessions, including unusual source IPs, off-hours access, or atypical file transfers.
  • Correlate MOVEit Transfer SFTP activity with identity provider or directory authentication events to find sessions with no matching authentication.
  • Track for exploitation attempts against the SFTP service and review Progress advisory indicators if published.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5806 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-34362Progress MOVEit Transfer SQL injection allows unauthenticated database accessProgress MOVEit Transfer contains a SQL injection flaw in its web application that lets an unauthenticated attacker reach and manipulate the underlyi…KEVEPSS 100%analysed9.8CVE-2026-15966Progress moveit transfer vulnerabilityPermissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before …EPSS 0.37%9.8CVE-2026-15967Progress moveit transfer insufficient session expiration vulnerabilityInsufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before …EPSS 0.37%9.8CVE-2026-10697Progress moveit transfer improper authentication vulnerabilityImproper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.EPSS 0.60%9.8CVE-2026-8801Progress moveit transfer vulnerabilityPath equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0…EPSS 0.55%9.8CVE-2026-8649Progress moveit transfer vulnerabilityImproper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affect…EPSS 0.46%9.8CVE-2024-6576Progress moveit transfer improper authentication vulnerabilityImproper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: …EPSS 0.62%9.8CVE-2023-35708Progress MOVEit Transfer SQL injection allows unauthenticated database accessProgress MOVEit Transfer contains a SQL injection flaw in its web application that lets an unauthenticated attacker reach the backend database. A cra…EPSS 97%analysed

Source: NIST National Vulnerability Database (record CVE-2024-5806), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.