CVE-2026-96429: Flowring Agentflow 4.0 - SQL Injection
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable through the /WebAgenda/SMBAjaxConfigProcess.do endpoint. The available information does not state that authentication or any other prior access is required.
Which deployments should be considered exposed?
Flowring Agentflow 4.0 deployments are affected if they use a version from before 2025/08/08 and expose the vulnerable API endpoint. The available information does not specify whether the endpoint is enabled or reachable in a default configuration.
Which input should be investigated for signs of exploitation?
Review requests to /WebAgenda/SMBAjaxConfigProcess.do, particularly values supplied through the id parameter. The reported impact is arbitrary SQL command execution via SQL injection in that parameter.