8
CVE-2026-59689
- EPSS 0.17%
- Veröffentlicht 27.07.2026 12:25:22
- Zuletzt bearbeitet 11.08.2026 14:12:35
- CVE-Watchlists
- Unerledigt
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Progress ≫ Connection Manager For Objectscale Version < 7.2.63.3
Progress ≫ Ecs Connection Manager Version < 7.2.63.3
Progress ≫ Moveit Web Application Firewall Version < 7.2.63.3
Progress ≫ Loadmaster Version < 7.2.54.19
Progress ≫ Loadmaster Version >= 7.2.55.0 < 7.2.63.3
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.066 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@progress.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690