Loading market data...
← Back to CVE feed

CVE-2026-4048

HIGH CVSS 8.4 View on NVD ↗

Description

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Published: Apr 20, 2026 14:16 UTC Modified: Apr 20, 2026 19:05 UTC