CVE-2026-59689

Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An incorrect authorization vulnerability in several Progress Software appliances allows authenticated attackers to escalate privileges to root, resulting in full system compromise.

Executive summary

Multiple Progress Software appliances, including LoadMaster and MOVEit WAF, are susceptible to a privilege escalation vulnerability that grants root-level access to authenticated attackers.

Vulnerability

The products suffer from an incorrect authorization flaw (CWE-863) that allows an authenticated attacker with low privileges to escalate their access to root on the underlying appliance.

Business impact

An attacker who successfully escalates privileges to root gains complete control over the affected appliance. This level of access permits the theft of sensitive data, the installation of persistent backdoors, or the disruption of critical network traffic, justifying the high CVSS score of 8.0.

Remediation

Immediate Action: Apply the security updates provided by Progress Software immediately to reach the patched versions listed in the vendor advisory.

Proactive Monitoring: Monitor appliance system logs for signs of privilege escalation, unexpected root command execution, or unauthorized configuration changes.

Compensating Controls: Restrict administrative access to these appliances to a limited set of authorized personnel and ensure they are not exposed to the public internet.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability poses a critical risk to appliance security due to the potential for full system takeover. Organizations must treat this as a high-priority update and verify that all affected Progress Software installations are patched to the latest recommended versions to prevent unauthorized root access.