CVE-2026-59688: Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59688?
The severity of CVE-2026-59688 is rated as high with a score of 8.4.
How do I fix CVE-2026-59688?
To fix CVE-2026-59688, apply the latest security patches and updates provided by Progress Software for the affected products.
What products are affected by CVE-2026-59688?
CVE-2026-59688 affects Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF.
What type of vulnerability is CVE-2026-59688?
CVE-2026-59688 is an OS Command Injection vulnerability that allows an authenticated attacker to execute arbitrary commands.
Who is at risk from CVE-2026-59688?
Authenticated users with high privileges are at risk from CVE-2026-59688 if they exploit this vulnerability.