CVE-2026-15967: MOVEit Transfer refresh-token processing does not enforce updated account restrictions
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress MOVEit Transferto a version that resolves this vulnerability.Fixed in 2025.1.5 - Upgrade
Upgrade
Progress MOVEit Transferto a version that resolves this vulnerability.Fixed in 2026.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15967?
The severity of CVE-2026-15967 is high with a CVSS score of 7.5.
What impact does CVE-2026-15967 have on Progress MOVEit Transfer?
CVE-2026-15967 allows insufficient enforcement of updated account restrictions during refresh-token processing.
How do I fix CVE-2026-15967?
To fix CVE-2026-15967, upgrade Progress MOVEit Transfer to version 2026.0.3 or later.
Which versions of Progress MOVEit Transfer are affected by CVE-2026-15967?
CVE-2026-15967 affects all versions of Progress MOVEit Transfer before 2025.1.5 and from 2026.0.0 before 2026.0.3.
What types of attacks are possible due to CVE-2026-15967?
CVE-2026-15967 may allow unauthorized access to sensitive information due to insufficient session expiration.