OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
References
Configurations
Configuration 1 (hide)
|
History
01 May 2026, 17:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://community.progress.com/s/article/LoadMaster-Security-Vulnerabilites-CVE-2026-3517-CVE-2026-3518-CVE-2026-3519-CVE-2026-4048-CVE-2026-21876 - Vendor Advisory, Patch | |
| First Time |
Progress
Progress ecs Connection Manager Progress connection Manager For Objectscale Progress loadmaster |
|
| CPE | cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:* cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:* cpe:2.3:a:progress:loadmaster:*:*:*:*:ltsf:*:*:* cpe:2.3:a:progress:loadmaster:*:*:*:*:ga:*:*:* |
20 Apr 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 14:16
Updated : 2026-05-01 17:34
NVD link : CVE-2026-4048
Mitre link : CVE-2026-4048
CVE.ORG link : CVE-2026-4048
JSON object : View
Products Affected
progress
- ecs_connection_manager
- loadmaster
- connection_manager_for_objectscale
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
