Progress Software has recently addressed five critical vulnerabilities affecting its LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These flaws, identified as CVE-2026-59686 through CVE-2026-59690, could enable authenticated attackers to execute arbitrary commands and potentially gain root access to the affected systems.
Details of the Vulnerabilities
Three of the identified vulnerabilities are related to operating system command injection:
- CVE-2026-59686: Allows a highly privileged authenticated user to execute arbitrary commands via the LoadMaster management interface.
- CVE-2026-59687: Affects the Geo Location management interface, posing a similar command injection risk.
- CVE-2026-59688: Involves command injection within the backup and restore functionality, enabling attackers with high administrative privileges to run commands on the underlying operating system.
Exploitation of these command injection vulnerabilities could grant attackers complete control over the affected appliances.
The remaining two vulnerabilities pertain to broken access controls:
- CVE-2026-59689: An incorrect authorization flaw that allows a low-privilege authenticated user to escalate their permissions to root, providing unrestricted control over the LoadMaster system.
- CVE-2026-59690: A missing authorization vulnerability in the REST API, permitting low-privileged authenticated users to perform administrative operations beyond their assigned roles. This issue also affects Progress Kemp Multi-Tenant LoadMaster deployments.
Affected Versions and Recommended Actions
The vulnerabilities impact the following versions:
- Progress Kemp LoadMaster: Versions 7.2.63.27 and earlier.
- Progress ECS Connection Manager: Versions 7.2.63.27 and earlier.
- Progress Connection Manager for ObjectScale: Versions 7.2.63.2 and earlier.
- Kemp LoadMaster LTSF: Version 7.2.54.187 and earlier.
- Multi-Tenant LoadMaster: Version 7.1.35.157 and earlier.
Progress Software has released patches to address these vulnerabilities. Users are strongly advised to upgrade to the following versions:
- LoadMaster GA: Version 7.2.63.37.
- LoadMaster LTSF: Version 7.2.54.197.
- ECS Connection Manager and Connection Manager for ObjectScale: Version 7.2.63.37.
- Multi-Tenant LoadMaster: Version 7.1.35.167.
Administrators can verify their installed LoadMaster version through the web interface, where the version string appears in the upper-right corner, or via the appliance console during startup.
Security Recommendations
Given that these vulnerabilities require authentication, organizations should take the following steps to enhance security:
- Review administrative accounts and eliminate unnecessary privileged access.
- Enforce strong passwords and implement multi-factor authentication where available.
- Monitor management interface and REST API activity for unusual commands or configuration changes.
By promptly applying the recommended updates and adhering to these security practices, organizations can mitigate the risks associated with these vulnerabilities and safeguard their network infrastructure.
These vulnerabilities underscore the critical importance of regular software updates and vigilant access control measures. As cyber threats continue to evolve, maintaining up-to-date systems and implementing robust security protocols are essential to protect against potential exploits.