CRITICAL🇵🇱 Wersja polska

CVE-2026-2096

CVSS 9.3v4.0pub. 2026-02-10upd. 2026-02-13

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

🤖 AI Analysis
How it works

The vulnerability results from the lack of an authentication mechanism in a specific functionality of the Agentflow system. An attacker can remotely invoke this functionality over the network without possessing any credentials. This results in full access to database operations — reading, modifying, and deleting records.

Impact

An attacker can read sensitive data stored in the database without authentication, as well as modify or permanently delete it, which may lead to violation of data integrity and confidentiality as well as disruption of system operation.

Mitigation & patch

Apply patches available from the manufacturer in accordance with references (forum.flowring.com and TWCERT/CC)

Who is affected

Flowring Agentflow — versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Flowring Agentflow

    APP
    Flowring
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-2095CRITICAL9.3PL ✓same product

Pomijanie uwierzytelnienia w Flowring Agentflow — przejęcie tokenu dowolnego użytkownika

CVE-2025-3709CRITICAL9.8PL ✓same product

Flowring Agentflow — pominięcie blokady konta umożliwia atak brute force

CVE-2022-39036CRITICAL9.8PL ✓same product

Flowring Agentflow BPM — nieuwierzytelniony upload pliku i RCE

CVE-2026-2097HIGH8.7same product

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote atta...

CVE-2022-39038HIGH8.8same product

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user pr...