ZDI-CAN-30687: ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59689.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because exploitation requires authentication and can lead to remote privilege escalation on Progress Software Kemp LoadMaster, restrict authenticated access to the LoadMaster management/interface to trusted users and trusted network locations (e.g., IP allowlisting via firewall/ACL) until the issue is remediated.
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30687?
ZDI-CAN-30687 has a CVSS severity rating of 8.8, indicating a high risk.
How do I fix ZDI-CAN-30687?
To fix ZDI-CAN-30687, ensure that you apply the latest patches provided by Progress Software for Kemp LoadMaster.
What is the impact of ZDI-CAN-30687?
The impact of ZDI-CAN-30687 allows remote authenticated attackers to escalate their privileges on the affected systems.
Is authentication required to exploit ZDI-CAN-30687?
Yes, authentication is required to exploit the ZDI-CAN-30687 vulnerability.
Which software is affected by ZDI-CAN-30687?
ZDI-CAN-30687 affects Progress Software Kemp LoadMaster installations.