SB2026072949 - Multiple vulnerabilities in Progress LoadMaster



SB2026072949 - Multiple vulnerabilities in Progress LoadMaster

Published: July 29, 2026

Security Bulletin ID SB2026072949
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 40% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Command injection (CVE-ID: CVE-2026-59686)

CWE-ID: CWE-77 - Command injection

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary operating system commands.

The vulnerability exists due to command injection in the management interface when handling management requests. A remote privileged user can send a crafted request to execute arbitrary operating system commands.


2) Command injection (CVE-ID: CVE-2026-59687)

CWE-ID: CWE-77 - Command injection

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary operating system commands.

The vulnerability exists due to command injection in the Geo Location management interface when handling management requests. A remote privileged user can send a crafted request to execute arbitrary operating system commands.


3) Command injection (CVE-ID: CVE-2026-59688)

CWE-ID: CWE-77 - Command injection

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to execute arbitrary operating system commands.

The vulnerability exists due to command injection in the backup restore functionality when processing restore operations. A remote privileged user can submit crafted restore input to execute arbitrary operating system commands.


4) Incorrect authorization (CVE-ID: CVE-2026-59689)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to escalate privileges to root.

The vulnerability exists due to incorrect authorization in the appliance authorization mechanism when processing authenticated operations. A remote user can perform crafted actions to escalate privileges to root.


5) Missing Authorization (CVE-ID: CVE-2026-59690)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to perform privileged administrative operations.

The vulnerability exists due to missing authorization in the REST API when handling administrative requests. A remote user can send crafted API requests to perform privileged administrative operations.

The issue affects access to administrative operations that should not be available at the user's permission level.


Remediation

Install update from vendor's website.