CVE-2026-59689

HIGH

Progress LoadMaster Family - Authenticated Root Privilege Escalation

Title source: manual
STIX 2.1

Description

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

Scores

CVSS v3 8.0
EPSS 0.0017
EPSS Percentile 6.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (5)
Progress Software/ECS Connection Manager 7.2.60.0 - 7.2.63.3
Progress Software/LoadMaster 7.2.36 - 7.2.54.19
Progress Software/LoadMaster 7.2.36 - 7.2.63.3
Progress Software/MOVEit WAF 7.2.60.0 - 7.2.63.3
Progress Software/Object Scale Connection Manager 7.2.60.0 - 7.2.63.3
Published Jul 27, 2026
Tracked Since Jul 27, 2026