Progress LoadMaster OS Command Injection Remote Code Execution Vulnerability via Custom WAF Rule

Vulnerability

A remote code execution vulnerability has been identified in Progress LoadMaster versions through v7.2.62.2 and LTSF v7.2.54.16. This vulnerability allows authenticated attackers with 'All' permissions to execute arbitrary commands on the LoadMaster appliance. The issue arises from unsanitized input in custom Web Application Firewall (WAF) rule files during the file upload process, which can be exploited to inject and execute commands on the server.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected LoadMaster appliance.

Remediation

Progress LoadMaster has released a patch for this vulnerability in version v7.2.63.1 for the GA channel and v7.2.54.17 for the LTSF channel. Instructions for upgrading can be found on the Progress Community LoadMaster Download Hub.

Added: Apr 20, 2026, 2:26 PM
Updated: Apr 20, 2026, 2:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
7.5
exploitability
5.0
remediation
7.7
relevance
6.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.