Skip to content
Progress SoftwareCVE-2026-59690

Progress Software ECS Connection Manager: missing authorization

High8.0CVE-2026-59690 · Published Jul 27, 2026 · updated Aug 11, 2026

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

Progress Software advisory

Affected versions

PackageAffectedFixed in
ECS Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
LoadMaster
Product
>= 7.0.6, < 7.2.63.37.2.63.3
>= 7.0.6, < 7.2.54.197.2.54.19
MOVEit WAF
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Multi Tenant
Product
>= 7.1.29, < 7.1.35.167.1.35.16
Object Scale Connection Manager
Product
>= 7.2.60.0, < 7.2.63.37.2.63.3
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software ECS Connection Manager: improper authorization
High8.0Jul 27
Progress Software ECS Connection Manager: command injection
High8.4Jul 27
Progress Software MOVEit Transfer: cross-site scripting
High7.1Jul 23
Permissive cross-domain security policy with untrusted domains vulnerability in...
High7.5Jul 23

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.