ZDI-CAN-30687: ZDI-26-482: Progress Software Kemp LoadMaster enablexroot Use of Hard-Coded Cryptographic Key Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-59689.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Because exploitation requires authentication and can lead to remote privilege escalation on Progress Software Kemp LoadMaster, restrict authenticated access to the LoadMaster management/interface to trusted users and trusted network locations (e.g., IP allowlisting via firewall/ACL) until the issue is remediated.