go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Flowring|AgentFlow - 5 Vulnerabilities

TVN ID TVN-202606002
CVE ID CVE-2026-2095, CVE-2026-2096, CVE-2026-2097, CVE-2026-2098, CVE-2026-2099
CVSS CVE-2026-2095:
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2026-2096:
9.8 (Critical) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2026-2097:
8.8 (High) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2026-2098:
5.4 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVE-2026-2099:
5.4 (Medium) CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products CVE-2026-2095, CVE-2026-2096, CVE-2026-2097:
Agentflow all versions

CVE-2026-2098, CVE-2026-2099:
Agentflow 4.0
Description CVE-2026-2095(Authentication Bypass):
Unauthenticated remote attackers can exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.

CVE-2026-2096(Missing Authentication):
Unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

CVE-2026-2097(Arbitrary File Upload):
Authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

CVE-2026-2098(Reflected Cross-site Scripting):
Unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

CVE-2026-2099(Stored Cross-Site Scripting):
Authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
Solution CVE-2026-2095, CVE-2026-2096:
Please refer to the following official instructions and take the appropriate mitigation measures:
https://forum.flowring.com/post/view?bid=72&id=45611&tpg=1&ppg=1&sty=1#45939

CVE-2026-2097:
Please contact the vendor for appropriate mitigation measures.

CVE-2026-2098, CVE-2026-2099:
Update to version 4.0.0.1878.877 and later.
Credit CVE-2026-2095, CVE-2026-2096, CVE-2026-2097:
Sideman (DEVCORE)

CVE-2026-2098, CVE-2026-2099:
ChunHao Yang(CHTSecurity)
Public Date 2026-02-06
Top