CVE-2026-102455: DigiWin|EasyFlow - Insecure Deserialization
Published Sep 30, 2026
·Updated
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Affected Software
1 affected component
Digiwin EasyFlow .NET
Event History
Sep 30, 2026
CVE Published
via MITRE·08:29 AM
Data Sourced
via MITRE·08:29 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability can be exploited remotely without authentication or user interaction. An attacker needs to send maliciously crafted serialized content to the affected server.
2
What is the potential impact of successful exploitation?
A successful attacker can execute arbitrary code on the EasyFlow .NET server. The provided severity vector indicates potential high impact to confidentiality, integrity, and availability.