CRITICAL · 9.6

CVE-2026-8037

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting uns...

Vulnerability Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

CVSS Score

9.6

CRITICAL

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ProgressConnection Manager For Objectscale< 7.2.63.2
ProgressEcs Connection Manager< 7.2.63.2
ProgressMoveit Web Application Firewall< 7.2.63.2
ProgressLoadmaster< 7.2.54.18

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-8037?

CVE-2026-8037 is a vulnerability with a CVSS score of 9.6 (CRITICAL). OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting uns...

How severe is CVE-2026-8037?

CVE-2026-8037 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-8037?

Check the references section above for vendor advisories and patch information. Affected products include: Progress Connection Manager For Objectscale, Progress Ecs Connection Manager, Progress Moveit Web Application Firewall, Progress Loadmaster.