Description
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
Published: 2026-07-27
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE-2026-59687 vulnerability is an OS Command Injection flaw, classified as CWE-78, that allows an attacker who has authenticated with high-level privileges to execute arbitrary operating system commands through the Geo Location management interface. This capability can lead to full compromise of the affected appliance, exposing all data and services hosted on it. The description directly states that execution of arbitrary OS commands could result in complete system compromise.

Affected Systems

Affected products are Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. These products are impacted regardless of the specific version, as the CVE description does not list affected versions. Users should verify their installations against the Progress Software advisory linked in the references.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, and the EPSS score of 0.00717 (less than 1%) suggests a low to very low probability of exploitation in the general population; the vulnerability is not listed in the CISA KEV catalog. Attackers need to be authenticated with high privileges and must target the Geo Location management interface; thus the potential for exploitation is limited to privileged users but the impact would be total system compromise. Since the exploitation path requires legitimate administrative access, the risk to systems that enforce strict authentication controls may be reduced; however, any misconfigured or compromised accounts could be leveraged.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and apply an official vendor patch for CVE‑2026‑59687 from Progress Software as soon as it becomes available.
  • Restrict or disable the Geo Location Management Interface for users lacking the required high privileges, or enforce least privilege for any accounts that have access.
  • Monitor system logs for evidence of unexpected OS command execution and use host‑based intrusion detection to alert on suspicious activity.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
CPEs cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Vendors & Products Progress connection Manager For Objectscale
Progress moveit Web Application Firewall

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager
Vendors & Products Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.
Title Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Progress Connection Manager For Objectscale Ecs Connection Manager Loadmaster Moveit Waf Moveit Web Application Firewall Object Scale Connection Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-28T03:55:35.706Z

Reserved: 2026-07-06T13:14:43.248Z

Link: CVE-2026-59687

cve-icon Vulnrichment

Updated: 2026-07-27T15:39:19.518Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T13:18:22.080

Modified: 2026-08-11T14:13:02.147

Link: CVE-2026-59687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')