HIGH🇵🇱 Wersja polska

CVE-2026-2097

CVSS 8.7v4.0pub. 2026-02-10upd. 2026-02-13

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Flowring Agentflow

    APP
    Flowring
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-2096CRITICAL9.3PL ✓same product

Flowring Agentflow — brak uwierzytelnienia umożliwia manipulację bazą danych

CVE-2026-2095CRITICAL9.3PL ✓same product

Pomijanie uwierzytelnienia w Flowring Agentflow — przejęcie tokenu dowolnego użytkownika

CVE-2025-3709CRITICAL9.8PL ✓same product

Flowring Agentflow — pominięcie blokady konta umożliwia atak brute force

CVE-2022-39036CRITICAL9.8PL ✓same product

Flowring Agentflow BPM — nieuwierzytelniony upload pliku i RCE

CVE-2022-39038HIGH8.8same product

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user pr...