Impact
A missing authorization flaw allows an authenticated attacker with low privileges to execute privileged administrative operations through the REST API. The flaw permits actions that should be reserved for higher permission levels, effectively elevating the attacker’s capabilities and potentially compromising the entire system. The weakness is a classic authorization bypass, categorized as CWE-862.
Affected Systems
The vulnerability affects Progress Software products: LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant. No specific version information is provided in the available data.
Risk and Exploitability
The CVSS score of 8 indicates a high severity. The EPSS score < 1% indicates a very low exploitation probability and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector, inferred from the description, is through authenticated REST API calls, where an attacker already has access but can misuse privileged endpoints. If exploited, the attacker could gain full administrative control over affected systems.
OpenCVE Enrichment