Junglewise Threat Intelligence

CVE-2026-59689: Progress Software LoadMaster and MOVEit WAF privilege escalation

CVE-2026-59689 · Severity: high · CVSS 8 · Published 2026-07-27

Vendors: Progress Software.

Executive brief

Progress Software has identified a security vulnerability in several of its networking and file transfer products, including LoadMaster and MOVEit WAF. These products are used to manage network traffic and secure web applications. An attacker who already has basic access to the system could exploit this flaw to gain full administrative control, potentially leading to data theft or a complete shutdown of the affected services.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the management interface of several Progress Software appliances. The flaw allows a low-privileged, authenticated attacker to bypass intended access controls and escalate their privileges to the root level. The attack vector is classified as 'Adjacent,' meaning the attacker typically needs to be on the same local network or subnet as the appliance. Successful exploitation results in full system compromise, granting the attacker complete control over the appliance's configuration and data. Progress Software has released patches to address this issue in the affected product lines.

Affected products

  • Progress Software LoadMaster 7.2.36 < 7.2.63.3, 7.2.36 < 7.2.54.19
  • Progress Software ECS Connection Manager 7.2.60.0 < 7.2.63.3
  • Progress Software Object Scale Connection Manager 7.2.60.0 < 7.2.63.3
  • Progress Software MOVEit WAF 7.2.60.0 < 7.2.63.3

Timeline

  • 2026-07-27: advisory: Initial disclosure by Progress Software and NVD publication.

References