VYPR
Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026

IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer

CVE-2026-8651

Description

Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module).

This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.