VYPR

LoadMaster

by Process Software

CVEs (10)

  • CVE-2024-1212CriKEVFeb 21, 2024
    risk 0.88cvss 10.0epss 0.95

    Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

  • CVE-2024-2448HigMar 22, 2024
    risk 0.59cvss 8.4epss 0.55

    An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

  • CVE-2025-13447HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.27

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2025-13444HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.27

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2026-59688HigJul 27, 2026
    risk 0.55cvss 8.4epss 0.01

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the…

  • CVE-2026-59687HigJul 27, 2026
    risk 0.55cvss 8.4epss 0.01

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the…

  • CVE-2026-59686HigJul 27, 2026
    risk 0.55cvss 8.4epss 0.01

    An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the…

  • CVE-2026-59690HigJul 27, 2026
    risk 0.52cvss 8.0epss 0.00

    A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that…

  • CVE-2026-59689HigJul 27, 2026
    risk 0.52cvss 8.0epss 0.00

    An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting…

  • CVE-2024-2449HigMar 22, 2024
    risk 0.50cvss 7.5epss 0.13

    A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a…