Impact
The CVE-2026-59687 vulnerability is an OS Command Injection flaw, classified as CWE-78, that allows an attacker who has authenticated with high-level privileges to execute arbitrary operating system commands through the Geo Location management interface. This capability can lead to full compromise of the affected appliance, exposing all data and services hosted on it. The description directly states that execution of arbitrary OS commands could result in complete system compromise.
Affected Systems
Affected products are Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. These products are impacted regardless of the specific version, as the CVE description does not list affected versions. Users should verify their installations against the Progress Software advisory linked in the references.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of 0.00717 (less than 1%) suggests a low to very low probability of exploitation in the general population; the vulnerability is not listed in the CISA KEV catalog. Attackers need to be authenticated with high privileges and must target the Geo Location management interface; thus the potential for exploitation is limited to privileged users but the impact would be total system compromise. Since the exploitation path requires legitimate administrative access, the risk to systems that enforce strict authentication controls may be reduced; however, any misconfigured or compromised accounts could be leveraged.
OpenCVE Enrichment