CVE-2026-4048
8.4Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF
An OS command injection vulnerability in Progress ADC products allows authenticated attackers with administrative permissions to execute arbitrary commands via unsanitized WAF rule file uploads.
Executive summary
A critical OS command injection vulnerability exists in multiple Progress ADC products that allows authenticated administrators to achieve remote code execution on the underlying appliance.
Vulnerability
This vulnerability is an OS command injection (CWE-77) triggered by unsanitized input within a custom WAF rule file during the file upload process. Exploitation requires an authenticated user with "All" permissions to interact with the appliance.
Business impact
Successful exploitation of this vulnerability permits full remote code execution, granting an attacker complete control over the affected LoadMaster or connection manager appliance. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to lateral movement, complete compromise of network traffic inspection, or unauthorized access to backend infrastructure.
Remediation
Immediate Action: Update all affected Progress ADC appliances to version V7.2.63.0 or later as specified by the vendor advisory.
Proactive Monitoring: Review system access logs for unusual administrative activity or unexpected file upload events associated with WAF rule configurations.
Compensating Controls: Restrict administrative access to the appliance management interface to trusted, secure networks only, and implement strict least-privilege policies for user accounts to limit the number of users with "All" permissions.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing Progress ADC products should prioritize the immediate deployment of the V7.2.63.0 patch across all environments. Given the severity of remote code execution on security appliances, failure to patch these systems leaves internal network traffic and infrastructure exposed to significant risk.