CVE-2026-96430
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Exposed Dangerous Method or Function in the
/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote
authenticated users to execute arbitrary SQL commands via the sql parameter.
749
Exposed Dangerous Method or Function
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Access Control
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Read Application Data
Modify Application Data
Execute Unauthorized Code Or Commands
Other
Applicable Platforms
All platforms may be affected
https://zuso.ai/cve-advisory/advisory