CVE-2026-96440: Flowring Agentflow 4.0 - Improper Limitation of a Pathname to a Restricted Directory(Path Traversal)
Published Sep 29, 2026
·Updated
Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.
Affected Software
1 affected component
Flowring Agentflow=4.0
Event History
Sep 29, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated to exploit the vulnerable uploadFile.jsp endpoint. The issue affects Flowring Agentflow 4.0 versions before 2023/03/24.
2
What access does successful exploitation provide?
An authenticated attacker can use the path parameter to write files to arbitrary locations outside the intended upload directory.