OS Command Injection Vulnerability in Progress ADC LoadMaster Products
CVE-2026-3519

8.4HIGH

What is CVE-2026-3519?

A vulnerability in the Progress ADC LoadMaster products allows an authenticated attacker with VS Administration permissions to execute arbitrary commands on the appliance. This is made possible due to unsanitized input in the 'aclcontrol' command, potentially leading to significant security risks if exploited. It is crucial for administrators to review and apply necessary security measures to mitigate the impact of this vulnerability.

Affected Version(s)

ECS Connections Manager V7.2.49.0

LoadMaster V7.2.45.0

MOVEit WAF V7.2.62.0

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.