Progress SoftwareCVE-2026-59690
Progress Software ECS Connection Manager: missing authorization
High8.0CVE-2026-59690 · Published Jul 27, 2026 · updated Aug 11, 2026
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ECS Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| LoadMaster Product | >= 7.0.6, < 7.2.63.3 | 7.2.63.3 |
| >= 7.0.6, < 7.2.54.19 | 7.2.54.19 | |
| MOVEit WAF Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
| Multi Tenant Product | >= 7.1.29, < 7.1.35.16 | 7.1.35.16 |
| Object Scale Connection Manager Product | >= 7.2.60.0, < 7.2.63.3 | 7.2.63.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-862
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: improper authorization | High8.0 | LoadMaster 7.2.63.3+2 more |
| Jul 27 | Progress Software ECS Connection Manager: command injection | High8.4 | LoadMaster 7.2.63.3+2 more |
| Jul 23 | Progress Software MOVEit Transfer: cross-site scripting | High7.1 | 2025.1.5+1 more |
| Jul 23 | Permissive cross-domain security policy with untrusted domains vulnerability in... | High7.5 | 2025.1.5+1 more |