An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress connection Manager For Objectscale
Progress moveit Web Application Firewall |
|
| CPEs | cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:* cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:* cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:* cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Progress connection Manager For Objectscale
Progress moveit Web Application Firewall |
Mon, 27 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress ecs Connection Manager Progress loadmaster Progress moveit Waf Progress object Scale Connection Manager |
|
| Vendors & Products |
Progress
Progress ecs Connection Manager Progress loadmaster Progress moveit Waf Progress object Scale Connection Manager |
Mon, 27 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jul 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Title | Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-07-27T12:25:22.245Z
Updated: 2026-07-28T03:55:34.119Z
Reserved: 2026-07-06T13:14:43.248Z
Link: CVE-2026-59689
Updated: 2026-07-27T13:21:07.881Z
Status : Analyzed
Published: 2026-07-27T13:18:22.327
Modified: 2026-08-11T14:12:35.210
Link: CVE-2026-59689
No data.