8.4
CVE-2026-59686
- EPSS 0.74%
- Veröffentlicht 27.07.2026 12:22:05
- Zuletzt bearbeitet 11.08.2026 14:13:12
- CVE-Watchlists
- Unerledigt
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Progress ≫ Connection Manager For Objectscale Version < 7.2.63.3
Progress ≫ Ecs Connection Manager Version < 7.2.63.3
Progress ≫ Moveit Web Application Firewall Version < 7.2.63.3
Progress ≫ Loadmaster Version < 7.2.54.19
Progress ≫ Loadmaster Version >= 7.2.55.0 < 7.2.63.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.74% | 0.513 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@progress.com | 8.4 | 1.7 | 6 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690