OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Progress
Progress loadmaster |
|
| Vendors & Products |
Progress
Progress loadmaster |
Tue, 13 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Title | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ProgressSoftware
Published: 2026-01-13T14:31:56.911Z
Updated: 2026-01-14T04:57:18.760Z
Reserved: 2025-11-19T19:18:13.816Z
Link: CVE-2025-13447
Updated: 2026-01-13T21:37:21.401Z
Status : Awaiting Analysis
Published: 2026-01-13T15:15:58.060
Modified: 2026-01-14T16:26:00.933
Link: CVE-2025-13447
No data.