High severity8.4NVD Advisory· Published Jan 13, 2026· Updated Aug 10, 2026
CVE-2025-13444
CVE-2025-13444
Description
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Affected products
8- Progress Software/Multi Tenant LoadMasterv5Range: 7.2.39
(expand)+ 1 more
- (no CPE)
- cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*range: <7.2.54.16
- cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*Range: <7.2.62.2
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.62.2
- cpe:2.3:a:progress:moveit_web_application_firewall:7.2.62.1:*:*:*:*:*:*:*
- cpe:2.3:a:progress:multi-tenant_hypervisor:*:*:*:*:*:*:*:*Range: <7.1.35.15
- Range: 7.2.50
Patches
Vulnerability mechanics
References
4- community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
- community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447nvdVendor Advisory
News mentions
0No linked articles in our index yet.