OS Command Injection Vulnerability in Progress ADC LoadMaster Products
CVE-2026-3519
8.4HIGH
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 20 April 2026
What is CVE-2026-3519?
A vulnerability in the Progress ADC LoadMaster products allows an authenticated attacker with VS Administration permissions to execute arbitrary commands on the appliance. This is made possible due to unsanitized input in the 'aclcontrol' command, potentially leading to significant security risks if exploited. It is crucial for administrators to review and apply necessary security measures to mitigate the impact of this vulnerability.
Affected Version(s)
ECS Connections Manager V7.2.49.0
LoadMaster V7.2.45.0
MOVEit WAF V7.2.62.0