CVE-2026-59688
Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
An OS command injection vulnerability exists in several Progress Software appliances that allows high privileged users to execute arbitrary commands via the backup restore functionality.
Executive summary
A critical OS command injection vulnerability in multiple Progress Software products allows authenticated, high privileged attackers to achieve full system compromise.
Vulnerability
This is an OS command injection flaw (CWE-78) triggered through the backup restore functionality. It requires an attacker to possess high privileges, meaning the threat originates from an already authenticated user with administrative access.
Business impact
Successful exploitation allows an attacker to execute arbitrary operating system commands, potentially leading to total system compromise of the affected appliance. While the CVSS score of 8.4 reflects the high severity and potential for full impact, the requirement for high privileges limits the attack surface to internal or compromised administrative accounts.
Remediation
Immediate Action: Update the affected Progress Software appliances to the versions specified in the vendor security bulletin.
Proactive Monitoring: Audit administrative access logs for unusual backup or restore activity, and monitor system processes for unauthorized command execution.
Compensating Controls: Restrict access to administrative interfaces to trusted management subnets only to prevent unauthorized use of high privilege accounts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should prioritize applying the vendor provided updates immediately to remediate this command injection risk. Given the potential for total system compromise, ensure that administrative credentials are rotated if there is any suspicion of unauthorized access to the management console.