← Back to browse · API

CVE-2026-3517

Severity
HIGH
CVSS
8.4
EPSS
0.18238
Risk score
39.98
CISA KEV
No
PoC
No
Published
2026-04-20
Modified
2026-04-22
First seen
2026-08-07
Aliases
EUVD-2026-23856, GHSA-RW4J-JHFH-FR2H
Products
Progress Software:ECS Connections Manager 7.2.49.0 <V7.2.63.0, Progress Software:LoadMaster 7.1.32.0 <V7.2.63.0, Progress Software:MOVEit WAF 7.2.62.0 <V7.2.63.0, Progress Software:Object Scale Connection Manager 7.2.62.0 <V7.2.63.0
Sources
euvd EUVD-2026-23856

Description

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command

References