Database/Control plane, storage & DevOps

Progress Kemp LoadMaster Multi Tenant: TENANT ISOLATION: the Multi Tenant product line's REST API doesn't check whether
Impact
TENANT ISOLATION: the Multi Tenant product line's REST API doesn't check whether a caller's permission level actually allows the administrative operation they're requesting. A low-privileged tenant account can invoke privileged administrative operations meant only for the LoadMaster operator, reaching functionality that should be walled off from other tenants sharing the same appliance.
Who can reach it
Requires an authenticated low-privilege account on the Multi Tenant platform — no privilege escalation exploit needed, just calling the REST API endpoints the UI hides but the backend doesn't actually gate.
What to do
Software upgrade to the fixed release per Progress's July 2026 LoadMaster Critical Security Bulletin (issued alongside four related CVEs). Prioritize this on any shared/multi-tenant LoadMaster deployment, since the whole point of the missing check is that tenant boundaries aren't being enforced.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.