Description
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Published: 2026-07-27
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS Command Injection flaw (CWE‑78) exists in the management interface of Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An attacker who is authenticated and holds high‑level privileges can supply arbitrary shell commands that the appliance then executes. This leads to total control over the operating system, allowing data exfiltration, installation of malware, or denial of service against the affected infrastructure.

Affected Systems

The affected products include Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager and MOVEit WAF. No specific version ranges are listed in the CNA data; therefore it is unclear which build numbers are vulnerable. Any deployment of the listed products that has not yet applied the vendor’s security fix should be considered at risk.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity vulnerability. The EPSS score of 0.00734 (<1%) indicates a very low probability of exploitation, and the lack of a KEV listing suggests it has not yet been widely abused in the wild. The attacker must be authenticated with high‑level privileges and is expected to use the web‑based management interface; this is inferred from the description and is not explicitly stated in the advisory.

Generated by OpenCVE AI on August 3, 2026 at 17:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Progress Software’s latest patch or security fix for the OS command injection vulnerability.
  • Configure the management interface to accept traffic only from trusted IP addresses or through a dedicated VPN tunnel.
  • Enforce least‑privilege by restricting access to the management interface to only those accounts that absolutely require it, and consider disabling high‑privilege accounts if they are not needed.

Generated by OpenCVE AI on August 3, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
CPEs cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Vendors & Products Progress connection Manager For Objectscale
Progress moveit Web Application Firewall

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager
Vendors & Products Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.
Title Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Progress Connection Manager For Objectscale Ecs Connection Manager Loadmaster Moveit Waf Moveit Web Application Firewall Object Scale Connection Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-28T03:55:37.387Z

Reserved: 2026-07-06T13:14:43.248Z

Link: CVE-2026-59686

cve-icon Vulnrichment

Updated: 2026-07-27T15:43:03.202Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T13:18:21.947

Modified: 2026-08-11T14:13:12.220

Link: CVE-2026-59686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')