CVE-2026-4048

8.4

Progress Software · LoadMaster, ECS Connections Manager, Object Scale Connection Manager, MOVEit WAF

An OS command injection vulnerability in Progress ADC products allows authenticated attackers with administrative permissions to execute arbitrary commands via unsanitized WAF rule file uploads.

Executive summary

A critical OS command injection vulnerability exists in multiple Progress ADC products that allows authenticated administrators to achieve remote code execution on the underlying appliance.

Vulnerability

This vulnerability is an OS command injection (CWE-77) triggered by unsanitized input within a custom WAF rule file during the file upload process. Exploitation requires an authenticated user with "All" permissions to interact with the appliance.

Business impact

Successful exploitation of this vulnerability permits full remote code execution, granting an attacker complete control over the affected LoadMaster or connection manager appliance. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to lateral movement, complete compromise of network traffic inspection, or unauthorized access to backend infrastructure.

Remediation

Immediate Action: Update all affected Progress ADC appliances to version V7.2.63.0 or later as specified by the vendor advisory.

Proactive Monitoring: Review system access logs for unusual administrative activity or unexpected file upload events associated with WAF rule configurations.

Compensating Controls: Restrict administrative access to the appliance management interface to trusted, secure networks only, and implement strict least-privilege policies for user accounts to limit the number of users with "All" permissions.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Progress ADC products should prioritize the immediate deployment of the V7.2.63.0 patch across all environments. Given the severity of remote code execution on security appliances, failure to patch these systems leaves internal network traffic and infrastructure exposed to significant risk.

More Progress Software CVEs

Sources