CVE-2026-96431
Received Received - Intake

Unrestricted File Upload in Flowring Agentflow 4.0

Vulnerability report for CVE-2026-96431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: ZUSO Advanced Research Team (ZUSO ART)

Description

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zuso.ai flowring_agentflow to 2023-03-24 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unrestricted file upload issue in Flowring Agentflow 4.0 before 2023/03/24. It allows remote authenticated users to upload dangerous file types via the /WebAgenda/download/uploadFile.jsp API endpoint. Attackers can exploit this to execute arbitrary system commands on the server.

Detection Guidance

Check for unauthorized file uploads to /WebAgenda/download/uploadFile.jsp in Flowring Agentflow 4.0 before 2023/03/24. Monitor for unexpected system command execution or suspicious file types uploaded by authenticated users.

Impact Analysis

This vulnerability can lead to complete system compromise. Attackers could gain control over the server, steal sensitive data, install malware, or disrupt services. Since it requires authentication, attackers must first obtain valid credentials.

Compliance Impact

This vulnerability likely violates compliance requirements for GDPR and HIPAA due to unauthorized access and potential data breaches. It could result in legal penalties, loss of certification, and reputational damage for organizations handling sensitive data.

Mitigation Strategies

Upgrade Flowring Agentflow to version 2023/03/24 or later. Restrict file upload permissions to trusted users only. Implement strict file type validation for uploaded files. Disable or restrict access to the /WebAgenda/download/uploadFile.jsp endpoint if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart