← Back to browse · API

CVE-2025-13447

Severity
HIGH
CVSS
8.4
EPSS
0.25389
Risk score
42.49
CISA KEV
No
PoC
No
Published
2026-01-13
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2026-2346, GHSA-PPF5-XM45-3XC6
Products
Progress Software:LoadMaster 7.1.32 <V7.2.54.16, Progress Software:LoadMaster 7.1.32 <V7.2.62.2, Progress Software:LoadMaster 7.2.37 <V7.2.54.16, Progress Software:LoadMaster 7.2.37 <V7.2.62.2, Progress Software:LoadMaster 7.2.39 <V7.2.54.16, Progress Software:LoadMaster 7.2.39 <V7.2.62.2, Progress Software:LoadMaster 7.2.50 <V7.2.54.16, Progress Software:LoadMaster 7.2.50 <V7.2.62.2
Sources
euvd EUVD-2026-2346

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

References