Skip to content
Progress SoftwareCVE-2026-59689

Progress Software ECS Connection Manager: improper authorization

High8.0CVE-2026-59689 · Published Jul 27, 2026 · updated Aug 11, 2026

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.

Progress Software advisory

Affected versions

PackageAffectedFixed in
ECS Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
LoadMaster
Product
>= 7.2.36, < 7.2.63.37.2.63.3
>= 7.2.36, < 7.2.54.197.2.54.19
MOVEit WAF
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Object Scale Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: missing authorization
High8.0Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software MOVEit Transfer: cross-site scripting
High7.1Jul 23
Permissive cross-domain security policy with untrusted domains vulnerability in...
High7.5Jul 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.