CVE-2026-59689
Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF
An incorrect authorization vulnerability in several Progress Software appliances allows authenticated attackers to escalate privileges to root, resulting in full system compromise.
Executive summary
Multiple Progress Software appliances, including LoadMaster and MOVEit WAF, are susceptible to a privilege escalation vulnerability that grants root-level access to authenticated attackers.
Vulnerability
The products suffer from an incorrect authorization flaw (CWE-863) that allows an authenticated attacker with low privileges to escalate their access to root on the underlying appliance.
Business impact
An attacker who successfully escalates privileges to root gains complete control over the affected appliance. This level of access permits the theft of sensitive data, the installation of persistent backdoors, or the disruption of critical network traffic, justifying the high CVSS score of 8.0.
Remediation
Immediate Action: Apply the security updates provided by Progress Software immediately to reach the patched versions listed in the vendor advisory.
Proactive Monitoring: Monitor appliance system logs for signs of privilege escalation, unexpected root command execution, or unauthorized configuration changes.
Compensating Controls: Restrict administrative access to these appliances to a limited set of authorized personnel and ensure they are not exposed to the public internet.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This vulnerability poses a critical risk to appliance security due to the potential for full system takeover. Organizations must treat this as a high-priority update and verify that all affected Progress Software installations are patched to the latest recommended versions to prevent unauthorized root access.