OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command
References
Configurations
Configuration 1 (hide)
|
History
01 May 2026, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.progress.com/s/article/LoadMaster-Security-Vulnerabilites-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 - Vendor Advisory | |
| First Time |
Progress
Progress ecs Connection Manager Progress connection Manager For Objectscale Progress loadmaster |
|
| CPE | cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:* cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:* cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:* cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:* |
20 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 14:16
Updated : 2026-05-01 18:20
NVD link : CVE-2026-3517
Mitre link : CVE-2026-3517
CVE.ORG link : CVE-2026-3517
JSON object : View
Products Affected
progress
- ecs_connection_manager
- loadmaster
- connection_manager_for_objectscale
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
