CVE-2026-8037 PUBLISHED

OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

Assigner: ProgressSoftware
Reserved: 06.05.2026 Published: 04.06.2026 Updated: 04.06.2026

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor Progress Software
Product LoadMaster
Versions Default: unaffected
  • affected from V7.2.60.0 to V7.2.63.2 (excl.)
  • affected from V7.2.45.12 to V7.2.54.18 (excl.)
Vendor Progress Software
Product ECS Connections Manager
Versions Default: unaffected
  • affected from V7.2.60.0 to V7.2.63.2 (excl.)
Vendor Progress Software
Product Object Scale Connection Manager
Versions Default: unaffected
  • affected from V7.2.60.0 to V7.2.63.2 (excl.)
Vendor Progress Software
Product MOVEit WAF
Versions Default: unaffected
  • affected from V7.2.60.0 to V7.2.63.2 (excl.)

Workarounds

plain text

Credits

  • Jacky Yang and Syed Ibrahim Ahmed of TrendAI Research finder

References

Problem Types

  • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE

Impacts

  • An unauthenticated remote attacker exploits unsanitized input in the LoadMaster API command endpoints to inject arbitrary OS commands, resulting in full remote code execution on the appliance.