Executive brief
LoadMaster is a network load balancer appliance used to distribute traffic across servers and ensure service availability. This vulnerability allows an authenticated administrator with user management permissions to inject arbitrary operating system commands through unsanitized API parameters, potentially gaining complete control of the appliance and compromising all services it protects.
Technical details
The vulnerability is an OS command injection flaw in Progress LoadMaster's API that fails to properly sanitize input parameters. An authenticated attacker with "User Administration" permissions can exploit this by crafting malicious API requests containing shell metacharacters and command payloads. The vulnerability is reachable via network through the API interface and requires valid credentials with administrative scope. Successful exploitation allows arbitrary command execution with the privileges of the LoadMaster process, potentially enabling complete system compromise, data theft, or service disruption.
Affected products
- Progress LoadMaster
Timeline
- 2026-01-13: disclosed