Progress · Adc Loadmaster · CVE-2026-3517
**Name of the Vulnerable Software and Affected Versions**
Progress ADC LoadMaster (affected versions not specified)
**Description**
An OS command injection flaw in the API allows an authenticated attacker with Geo Administration permissions to execute arbitrary commands on the appliance. This is possible due to unsanitized input in the 'addcountry' command.
**Recommendations**
Update to the latest version.
As a temporary workaround, restrict access to the 'addcountry' command to minimize the risk of exploitation.