OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-20 14:16
Updated : 2026-06-17 10:55
NVD link : CVE-2026-4048
Mitre link : CVE-2026-4048
CVE.ORG link : CVE-2026-4048
JSON object : View
Products Affected
progress
- connection_manager_for_objectscale
- ecs_connection_manager
- loadmaster
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
