CVE-2026-5964: Digiwin|EasyFlow .NET - SQL Injection
Published Apr 20, 2026
·Updated
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected Software
5 affected components
Digiwin EasyFlow .NET
Digiwin EasyFlow .NET>=6.6.0<=6.6.17
Digiwin EasyFlow .NET=6.1.0
Digiwin EasyFlow .NET=8.1.1
Digiwin EasyFlow .NET=8.1.2
Remediation
Information
Update to version 8.1.3 or later, or install patch 2025/07/15.
Event History
Apr 20, 2026
CVE Published
via MITRE·07:36 AM
Data Sourced
via MITRE·07:36 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5964?
CVE-2026-5964 has a high severity due to its potential for unauthorized access and data manipulation.
2
How do I fix CVE-2026-5964?
To fix CVE-2026-5964, update Digiwin EasyFlow .NET to the latest version provided by the vendor.
3
What types of attacks are possible with CVE-2026-5964?
CVE-2026-5964 allows attackers to perform SQL injection attacks, enabling them to read, modify, or delete database contents.
4
Who is affected by CVE-2026-5964?
Users of Digiwin EasyFlow .NET are affected by CVE-2026-5964 due to the SQL injection vulnerability.
5
Is authentication required to exploit CVE-2026-5964?
No, CVE-2026-5964 can be exploited by unauthenticated remote attackers.