High severity8.0NVD Advisory· Published Jul 27, 2026· Updated Aug 11, 2026
CVE-2026-59690
CVE-2026-59690
Description
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
Affected products
10- cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:moveit_web_application_firewall:*:*:*:*:*:*:*:*Range: <7.2.63.3
- cpe:2.3:a:progress:multi-tenant_loadmaster:*:*:*:*:*:*:*:*Range: <7.1.35.16
Patches
Vulnerability mechanics
References
1News mentions
4- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- ZDI-26-481: Progress Software Kemp LoadMaster access Missing Authorization Privilege Escalation VulnerabilityZero Day Initiative · Jul 29, 2026
- Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root AccessCyber Security News · Jul 28, 2026