CVE-2026-96430
Received Received - Intake

Exposed Dangerous Method in Flowring Agentflow API

Vulnerability report for CVE-2026-96430, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: ZUSO Advanced Research Team (ZUSO ART)

Description

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zuso.ai flowring_agentflow to 2026-08-28 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an exposed dangerous method in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 before 2026/08/28. It allows remote authenticated users to execute arbitrary SQL commands by manipulating the sql parameter.

Detection Guidance

Check for unusual SQL query patterns or unauthorized access to /WebAgenda/SQLWin.do. Monitor logs for requests containing the 'sql' parameter with suspicious values. Use network scanners to detect open ports and services associated with Flowring Agentflow 4.0.

Impact Analysis

An attacker could exploit this to execute arbitrary SQL commands, potentially leading to unauthorized data access, modification, or deletion in the database. This could compromise sensitive information or disrupt system operations.

Compliance Impact

This vulnerability could lead to unauthorized data access or breaches, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Update Flowring Agentflow to the latest version released after 2026/08/28. Restrict access to the /WebAgenda/SQLWin.do endpoint via firewall rules. Disable or remove the vulnerable API if not in use. Implement input validation for the 'sql' parameter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96430. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart