← Back to browse · API

CVE-2025-13444

Severity
HIGH
CVSS
8.4
EPSS
0.25389
Risk score
42.49
CISA KEV
No
PoC
No
Published
2026-01-13
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2026-2343, GHSA-XFX9-X566-2HWR
Products
Progress Software:LoadMaster 7.2.50 <V7.2.54.16, Progress Software:LoadMaster 7.2.50 <V7.2.62.2, Progress Software:Multi Tenant LoadMaster 7.2.39 <V7.1.35.15, progress:connection_manager_for_objectscale, progress:ecs_connection_manager, progress:loadmaster, progress:moveit_web_application_firewall, progress:multi-tenant_hypervisor
Sources
euvd EUVD-2026-2343
nvd CVE-2025-13444

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

References