OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96440

HIGH · CVSS 7.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability allows remote authenticated users to exploit a path traversal flaw in the /WebAgenda/download/uploadFile.jsp API of Flowring Agentflow 4.0, enabling them to write files to arbitrary locations outside the designated upload directory. This could lead to unauthorized file access or manipulation, posing a significant risk to the integrity and confidentiality of the system. Organizations using affected versions should prioritize remediation to mitigate potential data breaches or system compromise.

CVE
CVE-2026-96440
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.