What is CVE-2026-59686?
An OS Command Injection vulnerability in Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface. Immediate patching with the vendor's security update is recommended to prevent potential full appliance compromise.
Azərbaycanca: Progress Software-un LoadMaster, ECS Connection Manager, Object Scale Connection Manager və MOVEit WAF məhsullarında yüksək imtiyazlı autentifikasiya olunmuş istifadəçi tərəfindən idarəetmə interfeysi vasitəsilə özbaşına əməliyyat sistemi əmrlərinin icrasına imkan verən OS Command Injection zəifliyidir. Bu, təsirlənmiş cihazda tam nəzarətin ələ keçirilməsinə səbəb ola bilər. Təcili olaraq təchizatçı tərəfindən təqdim edilən təhlükəsizlik yamasının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Progress Software
FAQ2
Which Progress Software products are affected by CVE-2026-59686?
This OS Command Injection vulnerability affects LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF.
What can successful exploitation of CVE-2026-59686 lead to?
An authenticated attacker with high privileges can execute arbitrary operating system commands via the management interface, potentially leading to full compromise of the affected appliance.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.