A critical security vulnerability has been discovered in Progress OpenEdge, a platform for developing and deploying enterprise applications. The vulnerability, identified as CVE-2025-7388, allows remote code execution (RCE) and affects multiple versions of the software, allowing attackers to execute arbitrary commands with elevated system privileges.
See also: Vulnerability in PgAdmin allows unauthorized access

The vulnerability is located in the AdminServer component of Progress OpenEdge, specifically in the Java Remote Method Invocation (RMI) interface, which is used for remote administrative tasks. According to a security advisory, the flaw allows an authenticated but unauthorized user to manipulate configuration properties. This could lead to operating system command injection via the workDir.
Attackers can exploit this flaw by injecting malicious commands, which are executed with the elevated privileges of the AdminServer process, which often runs as NT AUTHORITY/SYSTEM on Windows.
The company has addressed the vulnerability and released patches in the Progress OpenEdge 12.2.18 and 12.8.9. The fix includes two key changes: first, it sanitizes the workDir parameter by surrounding values with double quotes to prevent command injection. Second, it disables the remote RMI feature by default to reduce the attack surface.
See also: PoC Exploit released for RCE vulnerability in ImageMagick

All versions of OpenEdge prior to these updates, including LTS releases 12.2.17 and 12.8.8 and their previous minor releases, are vulnerable. Systems running unpatched versions remain at significant risk, as weak authentication could allow attackers to compromise the entire system.
For users who have applied the code update, remote RMI will be disabled by default. Administrators who relied on this capability for remote operations will find that it no longer works. While it is possible to re-enable remote RMI, Progress warns that this reintroduces security risks and should only be done if there is a compelling business reason, at the user's responsibility.
For organizations that cannot apply updates immediately, temporary protective measures are recommended. These include restricting network access to the AdminServer RMI port (default 20931) using firewalls, running the AdminServer process with the lowest possible privileges, and removing any unused AdminServer plugins to minimize potential attack vectors. However, these measures are intended only for short‑term use. Progress strongly recommends that all customers upgrade to the patched versions to fully address the vulnerability.
See also: Critical vulnerability in Argo CD API exposes repository credentials

Users of the discontinued versions of Progress OpenEdge must upgrade to a supported version to receive the fix.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
