PT-2026-64905 · Progress · Ecs Connections Manager+4

CVE-2026-59690

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59690

Affected Products

Ecs Connections Manager
Loadmaster
Moveit Waf
Multi Tenant
Object Scale Connection Manager