CVE-2026-102454

Summary

EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Affected Software

VendorProductVersion RangeStatus
DigiWinEasyFlow .NET6.1.*affected
DigiWinEasyFlow .NET6.6 <= 6.6.19affected
DigiWinEasyFlow .NET8.1 <= 8.1.5affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References