Database/Control plane, storage & DevOps

Progress Kemp LoadMaster Multi Tenant: The Multi Tenant product line's REST API doesn't check whether a caller's
Impact
The Multi Tenant product line's REST API doesn't check whether a caller's permission level actually allows the administrative operation they're requesting. A low-privileged tenant account can invoke privileged administrative operations meant only for the LoadMaster operator, reaching functionality that should be walled off from other tenants sharing the same appliance.
Who can reach it
Requires an authenticated low-privilege account on the Multi Tenant platform — no privilege escalation exploit needed, just calling the REST API endpoints the UI hides but the backend doesn't actually gate.
What to do
Software upgrade to the fixed release per Progress's July 2026 LoadMaster Critical Security Bulletin (issued alongside four related CVEs). Prioritize this on any shared/multi-tenant LoadMaster deployment, since the whole point of the missing check is that tenant boundaries aren't being enforced.
References
Related entries
- Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSSCVE-2026-84665 · Jenkins SonarQube Scanner Plugin (dashboard link generation)High
- Jenkins Script Security Plugin (classpath entry approval): Script Security normally requires an administrator toCVE-2026-92127 · Jenkins Script Security Plugin (classpath entry approval)High
- Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UICVE-2026-92134 · Jenkins Warnings Plugin (analysis results ID validation)High
- Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UICVE-2026-92135 · Jenkins Coverage Plugin (coverage results ID validation)High
- Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSSCVE-2026-92136 · Jenkins OWASP Dependency-Check Plugin (report CWE rendering)High
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.