What is CVE-2026-59688?
CVE-2026-59688 is an OS Command Injection vulnerability found in Progress Software's LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF. This flaw allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance through the backup restore function. Immediate patching of the impacted systems is strongly recommended.
Azərbaycanca: CVE-2026-59688, Progress Software-un LoadMaster, ECS Connection Manager, Object Scale Connection Manager və MOVEit WAF məhsullarında aşkarlanmış OS Command Injection zəifliyidir. Bu boşluq yüksək səlahiyyətli autentifikasiya olunmuş təcavüzkara backup restore funksiyası vasitəsilə cihazda ixtiyari əməliyyat sistemi əmrləri icra etməyə imkan verir. Təsirlənən sistemlərin dərhal yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Progress Software
FAQ2
Which Progress Software products are affected by CVE-2026-59688?
This vulnerability affects LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF.
Through which function can an authenticated attacker exploiting CVE-2026-59688 execute commands?
The attacker can execute arbitrary operating system commands on the appliance through the backup restore function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.