CVE-2026-96430

Summary

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.

Affected Software

VendorProductVersion RangeStatus
Flowring Technology CorpAgentflow 4.00 < 2026/08/28affected

Weaknesses

  • CWE-749: CWE-749 Exposed dangerous method or function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References