OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96430

HIGH · CVSS 8.7 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Flowring Agentflow 4.0 version prior to August 28, 2026, contains a vulnerability in the /WebAgenda/SQLWin.do API endpoint that allows remote authenticated users to execute arbitrary SQL commands through the sql parameter. This could lead to unauthorized data manipulation or exposure, posing a significant risk to the integrity and confidentiality of the database. Organizations using this version should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-96430
Severity
HIGH
CVSS
8.7
EPSS
0.23%

Original NVD Description

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.