CVE-2026-59690
Progress Software · LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, Multi Tenant
A missing authorization vulnerability in various Progress Software products allows authenticated attackers with low privileges to perform unauthorized administrative actions via the REST API.
Executive summary
A missing authorization flaw in multiple Progress Software products enables low-privileged users to execute unauthorized administrative actions, creating a significant risk of system compromise.
Vulnerability
The application suffers from a missing authorization vulnerability (CWE-862) within its REST API, which allows an attacker with low-level authenticated access to perform privileged administrative operations that should be restricted based on their permission level.
Business impact
This vulnerability carries a CVSS score of 8.0, reflecting its high severity. Successful exploitation could allow a low-privileged user to gain unauthorized administrative control over critical infrastructure components, leading to full system compromise, loss of sensitive data, or severe service disruption.
Remediation
Immediate Action: Update the affected Progress Software products to the versions specified in the vendor security bulletin to resolve the authorization check deficiency.
Proactive Monitoring: Review REST API access logs for anomalous requests originating from low-privileged accounts that attempt to access administrative endpoints.
Compensating Controls: Restrict network access to the management REST API to trusted IP addresses only, effectively limiting the attack surface while planning for the necessary software updates.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the critical nature of the affected software, organizations should prioritize patching these components immediately. Failure to address this authorization gap exposes the management plane to unauthorized manipulation, which poses a severe risk to operational continuity.