CRITICAL🇵🇱 Wersja polska

CVE-2026-2095

CVSS 9.3v4.0pub. 2026-02-10upd. 2026-02-13

Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.

🤖 AI Analysis
How it works

An attacker without any prior authentication can exploit a specific functionality of the Agentflow system, which improperly verifies the identity of the requester. Exploitation of this functionality allows obtaining an authentication token assigned to a selected user account. With such a token, the attacker can log into the system with full permissions of that user, including potentially an administrative account.

Impact

An attacker can gain unauthorized access to the Agentflow system as any user, including an administrator, which can lead to complete system takeover, disclosure of sensitive data, and compromise of the integrity of processed information.

Mitigation & patch

Patches available from the vendor should be applied according to the references (forum.flowring.com and TWCERT/CC)

Who is affected

Flowring Agentflow — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Flowring Agentflow

    APP
    Flowring
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-2096CRITICAL9.3PL ✓same product

Flowring Agentflow — brak uwierzytelnienia umożliwia manipulację bazą danych

CVE-2025-3709CRITICAL9.8PL ✓same product

Flowring Agentflow — pominięcie blokady konta umożliwia atak brute force

CVE-2022-39036CRITICAL9.8PL ✓same product

Flowring Agentflow BPM — nieuwierzytelniony upload pliku i RCE

CVE-2026-2097HIGH8.7same product

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote atta...

CVE-2022-39038HIGH8.8same product

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user pr...