HIGH🇵🇱 Wersja polska

CVE-2026-59686

CVSS 8.4v3.1pub. 2026-07-27upd. 2026-08-11

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.

CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Progress Connection Manager For Objectscale

    APP
    Progress
    < 7.2.63.3
  • Progress Ecs Connection Manager

    APP
    Progress
    < 7.2.63.3
  • Progress Loadmaster

    OS
    Progress
    < 7.2.54.197.2.55.0 – 7.2.63.3 (excl.)
  • Progress Moveit Web Application Firewall

    APP
    Progress
    < 7.2.63.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-8037CRITICAL9.6⚠ KEVPL ✓same product

RCE przez command injection w API urządzeń Progress ADC (LoadMaster)

CVE-2024-1212CRITICAL10.0⚠ KEVPL ✓same product

Progress LoadMaster – nieuwierzytelnione RCE przez command injection w interfejsie zarządzania

CVE-2026-59689HIGH8.0PL ✓same product

Privilege escalation do root w produktach Progress Software (LoadMaster, ECS, MOVEit WAF)

CVE-2026-59687HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i powiązanych produktach via Geo Location

CVE-2026-59688HIGH8.4PL ✓same product

Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej