← Back

CVE-2026-59690

nvd nist
Published: Jul 27, 2026Modified: Aug 11, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: security@progress.com (Secondary)

Description

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

Affected (6)

5 products
Ecs Connection Manager
Loadmaster
Moveit Web Application Firewall
Multi Tenant Loadmaster
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.2.63.3
Before 7.2.63.3
Progress
Before 7.2.54.19
From 7.2.55.0 to 7.2.63.3
Before 7.2.63.3
Before 7.1.35.16

Timeline

No history available yet.