Missing Authorization in LoadMaster - CVE-2026-59690
Published: July 27, 2026 / Updated: July 29, 2026
LoadMaster
Detailed vulnerability description
The vulnerability allows a remote user to perform privileged administrative operations.
The vulnerability exists due to missing authorization in the REST API when handling administrative requests. A remote user can send crafted API requests to perform privileged administrative operations.
The issue affects access to administrative operations that should not be available at the user's permission level.