CVE-2026-102457

Summary

EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.

Affected Software

VendorProductVersion RangeStatus
DigiWinEasyFlow .NET6.1.*affected
DigiWinEasyFlow .NET6.6 <= 6.6.19affected
DigiWinEasyFlow .NET8.1 <= 8.1.5affected

Weaknesses

  • CWE-22: CWE-22 Improper Limitation of a Pathname to a Restricted Directory

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References