Threat Advisory

Kemp LoadMaster Flaws Let Attackers Gain Full System Control

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Kemp LoadMaster versions The flaws hit LoadMaster GA v7 have been identified in Kemp LoadMaster, a network traffic balancing appliance, that allow for OS command injection and privilege escalation. The flaws can lead to full system compromise on the affected appliance. The affected versions include LoadMaster GA v7.2.63.2 and earlier, LTSF builds v7.2.54.18 and earlier, and Multi-Tenant LoadMaster v7.1.35.15 and earlier.

CVE-2026-59686 (CVSS 8.4 — High Severity): The vulnerability allows a high-privilege user to run arbitrary commands on the appliance by passing unsanitized input into an operating system command through three separate management functions, including the main interface, Geo Location feature, and backup restore.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Kemp LoadMaster versions The flaws hit LoadMaster GA v7 have been identified in Kemp LoadMaster, a network traffic balancing appliance, that allow for OS command injection and privilege escalation. The flaws can lead to full system compromise on the affected appliance. The affected versions include LoadMaster GA v7.2.63.2 and earlier, LTSF builds v7.2.54.18 and earlier, and Multi-Tenant LoadMaster v7.1.35.15 and earlier.

CVE-2026-59686 (CVSS 8.4 — High Severity): The vulnerability allows a high-privilege user to run arbitrary commands on the appliance by passing unsanitized input into an operating system command through three separate management functions, including the main interface, Geo Location feature, and backup restore.[emaillocker id="1283"]

CVE-2026-59687 (CVSS 8.4 — High Severity): The vulnerability allows a high-privilege user to run arbitrary commands on the appliance by passing unsanitized input into an operating system command through three separate management functions, including the main interface, Geo Location feature, and backup restore.

CVE-2026-59688 (CVSS 8.4 — High Severity): The vulnerability allows a high-privilege user to run arbitrary commands on the appliance by passing unsanitized input into an operating system command through three separate management functions, including the main interface, Geo Location feature, and backup restore.

CVE-2026-59689 (CVSS 8 — Medium Severity): A low-privilege user can climb to root due to weak authorization checks in a management function. This grants an ordinary account administrative power.

CVE-2026-59690 (CVSS 8 — Medium Severity): A low-privilege user can access privileged REST API actions that the role should block, granting an ordinary account administrative power. These vulnerabilities collectively present a significant risk to organizations using Kemp LoadMaster. Administrators should apply the latest security updates now. These vulnerabilities collectively present a significant risk to organizations using Kemp LoadMaster.

These vulnerabilities collectively present a significant risk to organizations using Kemp LoadMaster.

RECOMMENDATION:

We recommend you to update Kemp LoadMaster to the version 7.2.63.3, 7.2.54.19, 7.1.35.16.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu