An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HProgress Connection Manager For Objectscale
APPProgress< 7.2.63.3Progress Ecs Connection Manager
APPProgress< 7.2.63.3Progress Loadmaster
OSProgress< 7.2.54.197.2.55.0 – 7.2.63.3 (excl.)Progress Moveit Web Application Firewall
APPProgress< 7.2.63.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
Related vulnerabilities
CVE-2026-8037CRITICAL9.6⚠ KEVPL ✓same product
RCE przez command injection w API urządzeń Progress ADC (LoadMaster)
CVE-2024-1212CRITICAL10.0⚠ KEVPL ✓same product
Progress LoadMaster – nieuwierzytelnione RCE przez command injection w interfejsie zarządzania
CVE-2026-59688HIGH8.4PL ✓same product
Command Injection w Progress LoadMaster i MOVEit WAF — funkcja przywracania kopii zapasowej
CVE-2026-59686HIGH8.4PL ✓same product
OS Command Injection w produktach Progress Software — zarządzanie przez interfejs admina
CVE-2026-59687HIGH8.4PL ✓same product
Command Injection w Progress LoadMaster i powiązanych produktach via Geo Location