Description
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
Published: 2026-07-27
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS Command Injection flaw exists in the backup restore functionality of Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. An authenticated attacker possessing high‑level privileges can cause the appliance to run arbitrary operating‑system commands, leading to a full system compromise. This weakness is a classic CWE-78 input‑to‑command injection.

Affected Systems

The vulnerability affects several Progress Software products: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. No specific version information is available in the advisory, so all current releases may be at risk.

Risk and Exploitability

The CVSS score of 8.4 classifies this as a high‑severity flaw. While the EPSS score is < 1%, the KEV listing indicates no widespread exploitation has been observed yet, but the need for authentic high privileges narrows the threat to internal users with advanced access. Exploitation would occur by triggering the backup restore path from an elevated account, causing remote command execution on the appliance.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor release that fixes the backup restore command injection issue.
  • If an urgent patch is unavailable, immediately disable the backup restore functionality or restrict its use to a restricted administrative account.
  • Enable strict role‑based access controls and audit logs for backup restore operations to detect potential misuse.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
CPEs cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Vendors & Products Progress connection Manager For Objectscale
Progress moveit Web Application Firewall

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager
Vendors & Products Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager

Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
Title Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Progress Connection Manager For Objectscale Ecs Connection Manager Loadmaster Moveit Waf Moveit Web Application Firewall Object Scale Connection Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-28T03:55:34.913Z

Reserved: 2026-07-06T13:14:43.248Z

Link: CVE-2026-59688

cve-icon Vulnrichment

Updated: 2026-07-27T15:38:35.770Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T13:18:22.203

Modified: 2026-08-11T14:12:51.893

Link: CVE-2026-59688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')