# CVE-2026-8037: Pre-Auth Command Injection RCE in Progress Kemp LoadMaster via Uninitialized-Heap escape_quotes() Flaw on /accessv2

> A critical unauthenticated OS command injection vulnerability (CVE-2026-8037, CVSS 9.8) in Progress Kemp LoadMaster's escape_quotes() sanitization routine allows an attacker to spray heap memory via the /accessv2 API endpoint's apiuser parameter, triggering an out-of-bounds read that smuggles a shell command into a system() call and yields root-level remote code execution. eSentire's Threat Response Unit observed exploitation attempts beginning June 29, 2026 that failed, but public PoC-quality technical writeups (watchTowr Labs) published the same day are expected to accelerate weaponized attacks against Internet-facing LoadMaster API endpoints.

- **Published:** 2026-07-01T00:00:00Z
- **Last reviewed:** 2026-08-08T12:22:35.831Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1045
- **ID:** TL-2026-1045
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 33 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-8037, CVE-2026-33691, CVE-2024-1212

## Description

CVE-2026-8037 is a pre-authentication remote code execution vulnerability in Progress Kemp LoadMaster, a widely deployed application delivery controller (ADC) / load balancer appliance. The root cause lies in the internal escape_quotes() function used to sanitize the apiuser and apipass parameters accepted by the /accessv2 API endpoint before they are concatenated into a shell command string ("validuser -b %s -u '%s' -p '%s'") and executed via system(). The vulnerable escape_quotes() implementation allocated its output buffer with malloc() (leaving it uninitialized) rather than calloc(), and — critically — failed to write a trailing NUL terminator after the escaped string was generated. escape_quotes() expands each embedded single-quote character into a four-byte sequence (\'\') to prevent shell metacharacter breakout; because heap allocations are not automatically zeroed and the function never terminates its output, a subsequent internal __sprintf_chk()/sprintf() call that consumes the escaped buffer can read past the intended end of the buffer and continue copying whatever bytes happen to sit in the adjacent heap chunk into the command line that is ultimately handed to system().

Researchers at watchTowr Labs (in coordination with the original discoverer, Syed Ibrahim Ahmed of TrendAI Research, working through Trend Micro's Zero Day Initiative as ZDI-26-342) demonstrated a full pre-auth exploit chain built on this primitive: the attacker first sends a crafted /accessv2 JSON request body containing dozens of extraneous key/value pairs whose values embed a shell command injection payload (e.g. "; cat /etc/passwd #") — a heap-spray technique intended to reliably place attacker-controlled bytes in memory adjacent to the buffer that will be under-terminated. The apiuser field is then populated with a value containing four single-quote characters, which escape_quotes() expands to sixteen bytes without a terminator, causing the adjacent, attacker-sprayed heap content to be read and copied into the command string built for system(). Because the composed command is executed as root via system(), the injected shell metacharacters and command execute with full root privileges on the appliance, with no authentication required and no user interaction.

The flaw affects LoadMaster GA v7.2.63.1 and earlier and LoadMaster LTSF v7.2.54.17 and earlier, when the device's management API is enabled (the default configuration on many deployments that use LoadMaster's REST API for automation). Progress fixed the issue in GA v7.2.63.2 and LTSF v7.2.54.18 by switching escape_quotes() to use calloc() (zero-initializing the buffer) and by explicitly writing a NUL terminator (*end = 0) after the escaped output. The fix was released as part of the Progress "LoadMaster Critical Security Bulletin — June 2026," alongside a related vulnerability, CVE-2026-33691, in the same LoadMaster API/UI component.

Progress originally reported (as of its June 4, 2026 advisory) no evidence of exploitation in the wild. That changed on June 29, 2026, when eSentire's Threat Response Unit (TRU) observed opportunistic scanning and exploitation attempts against the /accessv2 endpoint from three distinct source IPs; eSentire assessed the observed attempts as unsuccessful, noting no post-compromise activity resulted. However, watchTowr Labs' detailed public technical writeup — published the same week — walks through the full exploit chain (heap spray construction, quote-expansion math, and the sprintf/system() sink) in enough depth to substantially lower the bar for independent weaponization, and defenders should treat this as imminent-exploitation-risk infrastructure requiring urgent patching or compensating controls (disabling or firewalling the LoadMaster API) rather than a theoretical bug. LoadMaster's predecessor OS command injection vulnerability in the same API surface, CVE-2024-1212 (CVSS 10.0), was also actively exploited after disclosure, reinforcing that Kemp LoadMaster's API endpoints are a recurring target for command-injection-class attacks against edge network appliances.

## MITRE ATT&CK

- T1595 Active Scanning
- T1587 Develop Capabilities
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1489 Service Stop
- T1505 Server Software Component
- T1071 Application Layer Protocol
- T1036 Masquerading
- T1055 Process Injection
- T1005 Data from Local System
- T1552 Unsecured Credentials
- T1592 Gather Victim Host Information
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1087.001 Local Account
- T1027.010 Command Obfuscation

## Sources

- [The Hacker News: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth](https://thehackernews.com/2026/06/progress-kemp-loadmaster-flaw-could-let.html)
- [The Hacker News: Latest Progress Kemp LoadMaster Pre-Auth RCE coverage](https://thehackernews.com/2026/07/latest-progress-kemp-loadmaster-pre.html)
- [watchTowr Labs: Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)](https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/)
- [Zero Day Initiative Advisory ZDI-26-342](https://www.zerodayinitiative.com/advisories/ZDI-26-342/)
- [Progress LoadMaster Vulnerabilities Documentation](https://docs.progress.com/bundle/loadmaster-vulnerabilities-ga/page/Vulnerabilities.html)
- [Cyber Security News: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution](https://cybersecuritynews.com/critical-progress-kemp-loadmaster-vulnerability/)
- [GBHackers: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution](https://gbhackers.com/progress-kemp-loadmaster-vulnerability/)
- [CVEFeed: CVE-2026-8037 - OS Command Injection Remote Code Execution Vulnerability](https://cvefeed.io/vuln/detail/CVE-2026-8037)
- [SecurityOnline: Progress Kemp LoadMaster Alert - Multiple RCE and WAF Bypass Flaws Patched](https://securityonline.info/kemp-loadmaster-vulnerabilities-waf-bypass-os-injection/)
- [GuardianMSSP: Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth](https://www.guardianmssp.com/2026/06/30/progress-kemp-loadmaster-flaw-could-let-attackers-run-root-commands-pre-auth/)
- [teamwin: Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution](https://teamwin.in/critical-progress-kemp-loadmaster-vulnerability-enables-pre-auth-remote-code-execution/)
- [NVD: CVE-2026-8037 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-8037)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1045
