CVE-2026-59689
HIGH
8.0
CVSS 3.1
Description
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Metadata
Severity & Metrics
8.0
HIGH CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (4)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Progress Software | ECS Connection Manager | — | 7.2.60.0 < 7.2.63.3 |
| Progress Software | LoadMaster | — | 7.2.36 < 7.2.63.3, 7.2.36 < 7.2.54.19 |
| Progress Software | MOVEit WAF | — | 7.2.60.0 < 7.2.63.3 |
| Progress Software | Object Scale Connection Manager | — | 7.2.60.0 < 7.2.63.3 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-863 | cna | CWE-863: Incorrect Authorization |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 8.0 | HIGH | 3.1 | cna | CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |