ZDI-26-318: Progress Software Kemp LoadMaster ssodomain_killsession Command Injection Remote Code Execution Vulnerability
Published May 21, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-3518.
Affected Software
1 affected component
Progress Software Kemp LoadMaster
Event History
May 21, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-318?
The severity of ZDI-26-318 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-26-318?
To fix ZDI-26-318, apply the latest software update provided by Progress Software for Kemp LoadMaster.
3
What kind of attacks can be executed due to ZDI-26-318?
ZDI-26-318 allows remote code execution, enabling attackers to execute arbitrary commands on affected systems.
4
Is authentication required to exploit ZDI-26-318?
Yes, authentication is required to exploit the vulnerability identified in ZDI-26-318.
5
What software is affected by ZDI-26-318?
The vulnerability ZDI-26-318 affects installations of Progress Software Kemp LoadMaster.