CVE-2026-102454: DigiWin|EasyFlow .NET - Arbitrary File Upload
Published Sep 30, 2026
·Updated
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Affected Software
1 affected component
Digiwin EasyFlow .NET
Event History
Sep 30, 2026
CVE Published
via MITRE·08:26 AM
Data Sourced
via MITRE·08:26 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires a privileged remote attacker. The available information does not identify which privilege level or application role is required.
2
What is the likely impact of successful exploitation?
An attacker can upload and execute a web shell backdoor, enabling arbitrary code execution on the EasyFlow .NET server. The reported impact includes complete compromise of confidentiality, integrity, and availability.
3
Does exploitation require user interaction or a complex attack setup?
No user interaction is required, and the attack complexity is rated low. The vulnerable service must be remotely reachable to an attacker with the required privileges.