CVE-2026-59688
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
| CWE | CWE-78 |
| Vendor | progress software |
| Product | loadmaster |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for progress software loadmaster
Be the first to know when new high vulnerabilities affecting progress software loadmaster are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Progress Software / LoadMaster
7.2.40.0 < 7.2.63.3 7.2.40.0 < 7.2.54.19
Progress Software / ECS Connection Manager
7.2.60.0 < 7.2.63.3
Progress Software / Object Scale Connection Manager
7.2.60.0 < 7.2.63.3
Progress Software / MOVEit WAF
7.2.60.0 < 7.2.63.3