Progress SoftwareCVE-2026-59689
Progress Software ECS Connection Manager: improper authorization
High8.0CVE-2026-59689 · Published Jul 27, 2026 · updated Aug 11, 2026
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ECS Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| LoadMaster Product | >= 7.2.36, < 7.2.63.3 | 7.2.63.3 |
| >= 7.2.36, < 7.2.54.19 | 7.2.54.19 | |
| MOVEit WAF Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| Object Scale Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: missing authorization | High8.0 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 23 | Progress Software MOVEit Transfer: cross-site scripting | High7.1 | 2025.1.5+1 more |
| Jul 23 | Permissive cross-domain security policy with untrusted domains vulnerability in... | High7.5 | 2025.1.5+1 more |