CVE-2026-2095: Flowring|Agentflow - Authentication Bypass
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2095?
CVE-2026-2095 is classified as a high-severity vulnerability due to its potential for allowing unauthorized access.
How do I fix CVE-2026-2095?
To mitigate CVE-2026-2095, apply the latest security patches provided by Flowring for the Agentflow application.
Who is affected by CVE-2026-2095?
CVE-2026-2095 impacts all users of the Flowring Agentflow software that have not implemented the necessary security measures.
What type of vulnerability is CVE-2026-2095?
CVE-2026-2095 is an authentication bypass vulnerability that enables unauthenticated attackers to gain unauthorized access.
Can CVE-2026-2095 lead to data breaches?
Yes, CVE-2026-2095 can potentially lead to data breaches by allowing attackers to impersonate legitimate users.