{"id":1517,"date":"2026-06-30T10:32:14","date_gmt":"2026-06-30T10:32:14","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1517"},"modified":"2026-06-30T10:32:14","modified_gmt":"2026-06-30T10:32:14","slug":"progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1517","title":{"rendered":"Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 30, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ API Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjtFZGtJwnGA8dQHmNpd8Pzgx4p0wSq_e2hyphenhyphen2bZwWBQEDK8QPAi2CEOR_Nbns5jhRw9mMSPv6RBe2IqRO1c9fIMvMlUAV14B3VQE7-csMvfMQK6Qr3THGlxQY3C9HiYW_TYHGzok-TWFmMoMkto0OA8fNsQuvADEaJNFQYdIrXXzHGJEhyqpKRC2IFCaRM6\/s1700-e365\/loadmaster.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API.<\/p>\n<p>The flaw, tracked as\u00a0<b>CVE-2026-8037<\/b>, carries a CVSS score of\u00a0<a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-26-342\/\">9.8 according to ZDI<\/a>. A patch is available. If you run LoadMaster with the API enabled, update now.<\/p>\n<p>Progress\u00a0<a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Critical-Security-Bulletin-June-2026-CVE-2026-8037-CVE-2026-33691\">published its advisory on June 4<\/a>\u00a0and says it has not received any reports of exploitation. On June 29, researchers at\u00a0watchTowr Labs published a <a href=\"https:\/\/labs.watchtowr.com\/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037\/\">detailed<\/a> technical write-up\u00a0that walks through the full exploit chain.<\/p>\n<h2>What the Flaw Does<\/h2>\n<p>LoadMaster is an application delivery controller and load balancer used by enterprises to manage traffic across servers. It sits at the network edge, which makes any pre-auth flaw in it especially dangerous.<\/p>\n<p>The vulnerability lives in a function called\u00a0<b>escape_quotes()<\/b>, which is supposed to sanitize user input before it gets passed into a shell command. The function&#8217;s job is to escape single quotes so that an attacker cannot break out of a quoted string and inject commands. The problem: it allocated a memory buffer without clearing it first and never wrote a null terminator at the end of the sanitized string.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>That missing terminator is the whole exploit. Without it, the system keeps reading past the end of the sanitized input into whatever data happens to sit next to it in memory. An attacker can control what sits there by stuffing extra JSON keys into the same API request, each carrying a command injection payload. The system reads the sanitized input, keeps going, hits the attacker&#8217;s payload, and executes it.<\/p>\n<p>The attack targets the\u00a0<b>\/accessv2\u00a0<\/b>endpoint, which handles API credential validation. The attacker sends a JSON body with a specially crafted\u00a0apiuser\u00a0value and dozens of extra key-value pairs sprayed with the command they want to run. No valid credentials are needed. The command runs as root.<\/p>\n<h2>Affected Versions and Fix<\/h2>\n<p>The flaw affects LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older, when the API is enabled. Progress has released fixed versions: GA v7.2.63.2 and LTSF v7.2.54.18.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiR4ufDYRjg4d9LjrvECvtH9o43nseVfdQRIGpWF1jWin05z8wuyMWvo69GR650R6TPcOFhSsYbWexR-tWSTcRY1kVv8F0I_Mnr6zicjHEDjgAinA-c5ZfUZUgUP3u_cFgffUetsiSgTM8CVc6K0lnN_FGS5FtjA5IXeszrSxKW5au7QOr5iZAktRTWSJdB\/s1700-e365\/poc.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiR4ufDYRjg4d9LjrvECvtH9o43nseVfdQRIGpWF1jWin05z8wuyMWvo69GR650R6TPcOFhSsYbWexR-tWSTcRY1kVv8F0I_Mnr6zicjHEDjgAinA-c5ZfUZUgUP3u_cFgffUetsiSgTM8CVc6K0lnN_FGS5FtjA5IXeszrSxKW5au7QOr5iZAktRTWSJdB\/s1700-e365\/poc.png\" alt=\"\" border=\"0\" data-original-height=\"451\" data-original-width=\"1000\"\/><\/a><\/div>\n<p>The patch itself is minimal. Two changes: the memory allocation function was swapped from one that leaves the buffer uninitialized to one that zero-fills it, and an explicit null terminator was added after the escaped output. Two lines of code that close a path to the root.<\/p>\n<p>The vulnerability was\u00a0discovered by Syed Ibrahim Ahmed of TrendAI Research\u00a0and reported to Progress through the Zero Day Initiative on April 15, 2026. ZDI coordinated the public advisory release on June 9. watchTowr Labs independently analyzed the patch diff and published their own full technical breakdown with a working proof of concept on June 29.<\/p>\n<p>Progress also patched a second, high-severity flaw in the same advisory:\u00a0CVE-2026-33691, a WAF bypass where whitespace padding in filenames could circumvent file upload extension checks.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<h2>A Pattern Worth Watching<\/h2>\n<p>This is not LoadMaster&#8217;s first critical flaw. In November 2024, CISA\u00a0added a previous LoadMaster command injection flaw\u00a0(CVE-2024-1212, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after confirmed exploitation in the wild.<\/p>\n<p>In April 2026, Progress patched five more high-severity LoadMaster flaws, four of them command injection issues. Progress is also the maker of MOVEit, whose 2023 vulnerabilities fueled a mass exploitation campaign by the Cl0p ransomware group.<\/p>\n<p>The\u00a0<a href=\"https:\/\/www.cyber.gc.ca\/en\/alerts-advisories\/progress-security-advisory-av26-552\">Canadian Centre for Cyber Security<\/a>\u00a0has also issued an advisory urging administrators to apply the updates.<\/p>\n<p>No attacks on\u00a0CVE-2026-8037\u00a0have been reported yet. A working proof of concept is now public. Patch, and then ask whether the API needs to be reachable at all.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Jun 30, 2026Vulnerability \/ API Security A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1518,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[622,195,70,2250,2251,1040,1513,61,1774],"class_list":["post-1517","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attackers","tag-commands","tag-flaw","tag-kemp","tag-loadmaster","tag-preauth","tag-progress","tag-root","tag-run"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1517"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1517\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1518"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}