---
id: CVE-2025-13444
title: >-
  OS Command Injection Remote Code Execution Vulnerability in API in Progress
  LoadMaster allows an authenticated attacker with “User Administration”
  permissions to execute arbitrary commands on the LoadMaster appliance by
  exploiting unsani…
summary: >-
  OS Command Injection Remote Code Execution Vulnerability in API in Progress
  LoadMaster allows an authenticated attacker with “User Administration”
  permissions to execute arbitrary commands on the LoadMaster appliance by
  exploiting unsani…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: progress
product: connection_manager_for_objectscale
affected:
  - connection_manager_for_objectscale < 7.2.62.2
  - ecs_connection_manager < 7.2.62.2
  - moveit_web_application_firewall = 7.2.62.1
  - multi-tenant_hypervisor < 7.1.35.15
  - loadmaster < 7.2.54.16
  - 'loadmaster >= 7.2.55.0, < 7.2.62.2'
patched:
  - connection_manager_for_objectscale 7.2.62.2
  - ecs_connection_manager 7.2.62.2
  - multi-tenant_hypervisor 7.1.35.15
  - loadmaster 7.2.62.2
published: '2026-01-13'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13444'
references:
  - url: >-
      https://community.progress.com/s/article/Connection-Manager-for-ObjectScale-Vulnerabilities-CVE-2025-13444-CVE-2025-13447
    label: security@progress.com
  - url: >-
      https://community.progress.com/s/article/ECS-Connection-Manager-Vulnerabilities-CVE-2025-13444-CVE-2025-13447
    label: security@progress.com
  - url: >-
      https://community.progress.com/s/article/LoadMaster-Vulnerabilities-CVE-2025-13444-CVE-2025-13447
    label: security@progress.com
  - url: >-
      https://community.progress.com/s/article/MOVEit-WAF-Vulnerabilities-CVE-2025-13444-CVE-2025-13447
    label: security@progress.com
tags:
  - nvd
epss: 0.27217
epssPercentile: 0.97986
ingestedAt: '2026-08-11T16:47:03.868Z'
---

## Overview

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

## Affected

- `connection_manager_for_objectscale < 7.2.62.2`
- `ecs_connection_manager < 7.2.62.2`
- `moveit_web_application_firewall = 7.2.62.1`
- `multi-tenant_hypervisor < 7.1.35.15`
- `loadmaster < 7.2.54.16`
- `loadmaster >= 7.2.55.0, < 7.2.62.2`

## Remediation

Upgrade past the affected range:

- `connection_manager_for_objectscale 7.2.62.2`
- `ecs_connection_manager 7.2.62.2`
- `multi-tenant_hypervisor 7.1.35.15`
- `loadmaster 7.2.62.2`
