CVE-2026-96430: Flowring Agentflow 4.0 - Exposed Dangerous Method or Function
Published Sep 29, 2026
·Updated
Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.
Affected Software
1 affected component
Flowring Agentflow=4.0
Event History
Sep 29, 2026
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated to the affected Flowring Agentflow instance. The vulnerable interface is the /WebAgenda/SQLWin.do API endpoint.
2
What access does successful exploitation provide?
An authenticated attacker can execute arbitrary SQL commands by supplying them through the sql parameter.
3
Which versions are affected?
The issue affects Flowring Agentflow 4.0 versions before 2026/08/28.