Junglewise Threat Intelligence

CVE-2026-59686: Progress Software LoadMaster OS command injection in management interface

CVE-2026-59686 · Severity: high · CVSS 8.4 · Published 2026-07-27

Vendors: Progress Software Corporation.

Executive brief

Progress Software has identified a security flaw in several of its networking and data management appliances, including LoadMaster and MOVEit WAF. These devices are typically used to manage web traffic and secure data transfers. An attacker with administrative access to the management interface could exploit this vulnerability to take full control of the device, potentially leading to data theft or a complete shutdown of the services the appliance supports.

Technical details

An OS Command Injection vulnerability (CWE-78) exists in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. The flaw is located within the management interface and can be triggered by an authenticated attacker with high privileges. By sending specially crafted input to the management interface, the attacker can bypass input validation to execute arbitrary operating system commands with the privileges of the application. This can lead to a complete system compromise. The vulnerability is addressed in versions 7.2.63.3 and 7.2.54.19.

Affected products

  • Progress Software Corporation LoadMaster < 7.2.63.3, < 7.2.54.19
  • Progress Software Corporation ECS Connection Manager 7.2.60.0 - 7.2.63.2
  • Progress Software Corporation Object Scale Connection Manager 7.2.60.0 - 7.2.63.2
  • Progress Software Corporation MOVEit WAF 7.2.60.0 - 7.2.63.2

Timeline

  • 2026-07-27: advisory: Initial publication of the security bulletin by Progress Software.
  • 2026-07-27: disclosed

References