Executive brief
Progress Software has identified a security flaw in several of its networking and data management products, including LoadMaster and MOVEit WAF. This vulnerability allows a user with limited access to bypass security checks and perform administrative tasks they should not be allowed to do. If exploited, an attacker could gain full control over the system, potentially leading to data theft or service disruptions.
Technical details
A Missing Authorization vulnerability (CWE-862) exists in the REST API of Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant. The flaw allows an authenticated attacker with low-level privileges to execute administrative commands that should be restricted to higher-level accounts. The attack vector is listed as 'Adjacent' (AV:A), meaning the attacker must be on the same local network or subnet. Successful exploitation could result in a complete compromise of the affected system's confidentiality, integrity, and availability. Progress Software has released updates to address this issue in versions 7.2.63.3, 7.2.54.19, and 7.1.35.16.
Affected products
- Progress Software LoadMaster 7.0.6 to 7.2.63.2, 7.0.6 to 7.2.54.18
- Progress Software ECS Connection Manager 7.2.60.0 to 7.2.63.2
- Progress Software Object Scale Connection Manager 7.2.60.0 to 7.2.63.2
- Progress Software MOVEit WAF 7.2.60.0 to 7.2.63.2
- Progress Software Multi Tenant 7.1.29 to 7.1.35.15
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed