Status: EPSS-IMMINENT | Advisory ID: CVE-2026-4048
| CVE | CVE-2026-4048 |
| CVSS Score / Version | 8.4 (High) / CVSS v3.1 |
| CVSS Vector | CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is adjacent; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Progress LoadMaster, Progress Connection Manager for ObjectScale, and Progress ECS Connection Manager |
| Classified as | CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')) |
| Exploitation prediction (EPSS) | 4.18% probability of exploitation in the next 30 days (91% percentile) -- FIRST.org's EPSS model. |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Progress | LoadMaster | ||
| Progress | Connection Manager for ObjectScale | ||
| Progress | ECS Connection Manager |
| Subsystems | General OT |
| Sectors | Multi-sector |
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with βAllβ permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.
Monitor Progress's web page for any future patch releases. See vendor advisory link below.