CVE-2026-11903 Details
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.
A stored cross-site scripting vulnerability has been identified in the Ad Hoc module of Progress MOVEit Transfer. This issue allows an authenticated attacker to send a message containing a crafted JavaScript payload, which is then executed in the browser of the message recipient. The vulnerability affects MOVEit Transfer versions 2026.0.0 prior to 2026.0.1, 2025.1.0 prior to 2025.1.4, 2025.0.0 prior to 2025.0.8, and 2024.1.8 and earlier.
Users are advised to upgrade to MOVEit Transfer versions 2026.0.1, 2025.1.4, or 2025.0.8. For those on MOVEit Cloud, no action is required as the environment has already been updated to a patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.progress.com/s/article/MOVEit-Transfer-Critical-Security-Bulletin-June-2026 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress moveit transfer | <= 2024.1.8 >= 2025.0.0, < 2025.0.8 >= 2025.1.0, < 2025.1.4 2026.0.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |