CVE Vulnerabilities

CVE-2025-11235

Unverified Password Change

Published: Jan 07, 2026 | Modified: Feb 03, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.

Weakness

When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Affected Software

NameVendorStart VersionEnd Version
Moveit_transferProgress2022.0.0 (including)2022.0.10 (excluding)
Moveit_transferProgress2022.1.0 (including)2022.1.11 (excluding)
Moveit_transferProgress2023.0.0 (including)2023.0.8 (excluding)
Moveit_transferProgress2023.1.0 (including)2023.1.3 (excluding)

Potential Mitigations

References