CVE-2026-59690
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF,
CVSS
8.0
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Jul 27, 2026 · Last modified: Jul 27, 2026 · CWE-862
Not enough EPSS history yet.
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-664775.3 MED—
———Unauthenticated Broken Access Control in Gillion <= 4.13 versions.4hCVE-2026-664425.4 MED—
———Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.4hCVE-2026-655685.0 MED—
———Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.4hCVE-2026-655675.3 MED—
———Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.4hCVE-2026-654356.5 MED—
———Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.4hCVE-2026-654336.5 MED—
———Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions.4h