CVE-2026-102455
Received Received - Intake

Insecure Deserialization in EasyFlow .NET Allows Remote Code Execution

Vulnerability report for CVE-2026-102455, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: TWCERT/CC

Description

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
digiwin easyflow *-*-*-*-*-*-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

EasyFlow .NET by Digiwin has an insecure deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending specially crafted serialized data.

Detection Guidance

Detecting insecure deserialization vulnerabilities like this one typically requires network traffic inspection and application-level monitoring. Check for unusual serialized data in HTTP requests, especially POST requests with content types like application/x-java-serialized-object or similar. Monitor server logs for unexpected code execution or errors during deserialization. Use tools like Wireshark to capture and analyze network traffic for malformed serialized payloads.

Impact Analysis

This vulnerability allows attackers to run malicious code on the server without authentication. It could lead to full system compromise, data theft, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and security. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Immediately apply patches or updates from Digiwin for EasyFlow .NET. If patches are unavailable, disable deserialization features or implement strict input validation for serialized data. Use allowlists for trusted serialized objects and avoid using unsafe deserialization methods. Restrict network access to the application using firewalls and ensure proper authentication is enforced.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102455. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart