OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress loadmaster Progress multi-tenant Loadmaster |
|
| Vendors & Products |
Progress
Progress loadmaster Progress multi-tenant Loadmaster |
Tue, 13 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Title | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-01-13T14:26:50.661Z
Updated: 2026-01-14T04:57:17.749Z
Reserved: 2025-11-19T19:14:26.777Z
Link: CVE-2025-13444
Updated: 2026-01-13T21:37:04.277Z
Status : Awaiting Analysis
Published: 2026-01-13T15:15:57.913
Modified: 2026-01-14T16:26:00.933
Link: CVE-2025-13444
No data.