OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102458

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

EasyFlow .NET by Digiwin is vulnerable due to a missing authentication flaw that allows unauthenticated remote attackers to access other users' plaintext passwords via a specific API. This critical vulnerability poses a significant risk to user data integrity and confidentiality. Organizations using EasyFlow .NET should prioritize immediate remediation to protect against potential data breaches.

CVE
CVE-2026-102458
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.