Description
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
Published: 2026-07-27
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw allows an authenticated attacker with low privileges to execute privileged administrative operations through the REST API. The flaw permits actions that should be reserved for higher permission levels, effectively elevating the attacker’s capabilities and potentially compromising the entire system. The weakness is a classic authorization bypass, categorized as CWE-862.

Affected Systems

The vulnerability affects Progress Software products: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant. No specific version information is provided in the available data.

Risk and Exploitability

The CVSS score of 8 indicates a high severity. The EPSS score < 1% indicates a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector, inferred from the description, is through authenticated REST API calls, where an attacker already has access but can misuse privileged endpoints. If exploited, the attacker could gain full administrative control over affected systems.

Generated by OpenCVE AI on August 3, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided security patch for LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant.
  • Restrict REST API access to privileged roles only and remove or disable unauthorized endpoints.
  • Audit user and role assignments to enforce least privilege and remediate any unnecessary elevated permissions.

Generated by OpenCVE AI on August 3, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
Progress multi-tenant Loadmaster
CPEs cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:multi-tenant_loadmaster:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
Vendors & Products Progress connection Manager For Objectscale
Progress moveit Web Application Firewall
Progress multi-tenant Loadmaster

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Process Software
Process Software multi Tenant
Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager
Vendors & Products Process Software
Process Software multi Tenant
Progress
Progress ecs Connection Manager
Progress loadmaster
Progress moveit Waf
Progress object Scale Connection Manager

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
Title Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Process Software Multi Tenant
Progress Connection Manager For Objectscale Ecs Connection Manager Loadmaster Moveit Waf Moveit Web Application Firewall Multi-tenant Loadmaster Object Scale Connection Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-28T03:55:33.063Z

Reserved: 2026-07-06T13:14:43.248Z

Link: CVE-2026-59690

cve-icon Vulnrichment

Updated: 2026-07-27T13:20:49.775Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T13:18:22.457

Modified: 2026-08-11T14:11:42.970

Link: CVE-2026-59690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses