VYPR
patchPublished Jul 28, 2026· 1 source

Five Progress LoadMaster Vulnerabilities Threaten Appliance Compromise

Progress has patched five critical vulnerabilities in its LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale products, with three allowing command injection and two enabling privilege escalation.

Progress has released critical security updates to address five significant vulnerabilities impacting its LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. The flaws, cataloged as CVE-2026-59686 through CVE-2026-59690, affect older versions of these products and could potentially lead to complete appliance compromise if exploited by authenticated attackers. The company issued a security bulletin on July 27, 2026, noting that it has not received reports of active exploitation or observed direct operational impact on customers.

Three of the vulnerabilities are related to operating system command injection. CVE-2026-59686 allows a highly privileged authenticated attacker to execute arbitrary commands through the LoadMaster management interface. Similarly, CVE-2026-59687 poses a command injection risk via the Geo Location management interface, while CVE-2026-59688 enables command execution through the backup and restore functionality. Successful exploitation of these issues could grant an attacker full control over the affected appliance.

The remaining two vulnerabilities stem from broken access control mechanisms. CVE-2026-59689 is an incorrect authorization flaw that permits a low-privilege authenticated user to escalate their permissions to root, granting them unrestricted control over the LoadMaster system. This could allow for configuration changes, data access, persistence deployment, or service disruption.

Furthermore, CVE-2026-59690 is a missing authorization vulnerability within the REST API. This flaw enables low-privileged authenticated users to perform administrative operations that should be restricted based on their assigned roles. This vulnerability specifically impacts Progress Kemp Multi-Tenant LoadMaster deployments as well.

These vulnerabilities affect specific older versions of Progress Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale. For instance, LoadMaster versions 7.2.63.27 and earlier, ECS Connection Manager and Connection Manager for ObjectScale versions 7.2.63.2 and earlier, and Kemp LoadMaster LTSF version 7.2.54.187 and earlier are vulnerable. For Multi-Tenant LoadMaster, CVE-2026-59690 affects version 7.1.35.157 and earlier.

Progress strongly recommends immediate updates for all affected customers. Specific upgrade paths are provided: LoadMaster GA users should move to version 7.2.63.37, while LTSF users need to install version 7.2.54.197. ECS Connection Manager and Connection Manager for ObjectScale users should upgrade to version 7.2.63.37, and Multi-Tenant LoadMaster customers should transition to version 7.1.35.167.

Administrators can verify their current LoadMaster version through the web interface or the appliance console. Organizations running unsupported releases are urged to upgrade to a supported, fixed version, as older versions may no longer receive security patches. Given that these vulnerabilities require authentication, security best practices include reviewing administrative accounts, minimizing privileged access, enforcing strong passwords and multi-factor authentication, and closely monitoring management interface and REST API activity for suspicious commands or configuration changes.

Synthesized by Vypr AI