Vulnerability Intelligence Report
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
CVE-2026-59689
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
No Active Exploit Signals
CVSS Base Score
8.0
HIGH
Exploitability:2.1
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-863 ↗CWE-863: Incorrect Authorization
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Progress Software | LoadMaster | 7.2.36 < 7.2.63.3 (affected), 7.2.36 < 7.2.54.19 (affected) |
| Progress Software | ECS Connection Manager | 7.2.60.0 < 7.2.63.3 (affected) |
| Progress Software | Object Scale Connection Manager | 7.2.60.0 < 7.2.63.3 (affected) |
| Progress Software | MOVEit WAF | 7.2.60.0 < 7.2.63.3 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Progress Software Corporation · Vendor · USA |
| Reserved | 2026-07-06T13:14:43 |
| Published | 2026-07-27T12:25:22 |
| Last Updated | 2026-07-28T03:55:34 |
Community Chatter & Buzz