Description
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Published: 2026-07-27
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization that permits an authenticated low‑privileged user to elevate privileges to root on the appliance. This can lead to full system compromise, allowing an attacker to read, modify, or delete any data, install malware, or disrupt services. The weakness is identified as CWE‑863.

Affected Systems

Progress Software ECS Connection Manager, LoadMaster, Object Scale Connection Manager, and MOVEit WAF. Versions are not listed in the advisory; affected appliances should check the vendor for applicable patches.

Risk and Exploitability

The advisory assigns a CVSS score of 8, indicating high severity. The EPSS score is 0.00169, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, reducing confidence in widespread public exploitation but does not eliminate risk. The likely attack vector requires an attacker to be authenticated with a low‑privileged account; from there, the improper authorization can be leveraged through the appliance’s management interface to gain root access. No public exploit code is reported, but the high severity and privileged escalation potential make this a critical concern.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued patches or upgrade each product to the latest version that addresses CVE‑2026‑59689.
  • Remove or tightly restrict any low‑privileged accounts that have administrative access to the appliance and follow the principle of least privilege.
  • Enable and regularly review audit logs for unauthorized privilege changes and anomalous activity on the appliance.
  • Consider network segmentation or firewall rules to limit external access to the appliance’s management interface.

Generated by OpenCVE AI on August 3, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
CPEs cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Vendors & Products Progress connection Manager For Objectscale
Progress moveit Web Application Firewall

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager
Vendors & Products Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Title Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Progress Connection Manager For Objectscale Ecs Connection Manager Loadmaster Moveit Waf Moveit Web Application Firewall Object Scale Connection Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-28T03:55:34.119Z

Reserved: 2026-07-06T13:14:43.248Z

Link: CVE-2026-59689

cve-icon Vulnrichment

Updated: 2026-07-27T13:21:07.881Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T13:18:22.327

Modified: 2026-08-11T14:12:35.210

Link: CVE-2026-59689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T18:00:11Z

Weaknesses