What is CVE-2026-59687?
CVE-2026-59687 is an OS Command Injection vulnerability in various Progress Software products, including LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. It allows an authenticated, high-privileged attacker to execute arbitrary OS commands on the target appliance, exploiting the Geo Location management feature. Applying vendor-provided patches is critical for mitigation.
Azərbaycanca: CVE-2026-59687, istifadəçi autentifikasiyasından keçmiş yüksək səlahiyyətli hücumçuların Geo Location idarəetmə funksiyası vasitəsilə sistemdə ixtiyari əmrlər icra etməsinə imkan verən kritik bir zəiflikdir. Bu boşluq LoadMaster, ECS Connection Manager, Object Scale Connection Manager və MOVEit WAF daxil olmaqla bir sıra məhsullara təsir göstərir. Müdafiə üçün müvafiq yeniləmələrin tətbiqi vacibdir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Progress Software
FAQ2
What level of privileges does an attacker need to exploit CVE-2026-59687?
The attacker must be an authenticated, high-privileged user on the system.
Through which feature does CVE-2026-59687 allow arbitrary command execution?
This critical vulnerability allows arbitrary OS command execution through the Geo Location management feature.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.