SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59690

HIGH · CVSS 8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

A Missing Authorization vulnerability in multiple Progress Software products allows authenticated users with low privileges to execute privileged administrative operations through the REST API, bypassing intended access controls. This could lead to unauthorized system modifications and potential compromise. Organizations using these affected products should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-59690
Severity
HIGH
CVSS
8
EPSS
0.22%

Original NVD Description

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.

Related CVEs

Other vulnerabilities affecting the same vendor(s)