Missing Authentication Flaw in EasyFlow .NET by Digiwin
CVE-2026-102458
9.3CRITICAL
What is CVE-2026-102458?
The EasyFlow .NET product developed by Digiwin exposes a security flaw that allows unauthenticated remote attackers to access plaintext passwords belonging to other users via a specific API. This vulnerability emphasizes the critical need for proper authentication mechanisms to ensure user data is protected from unauthorized access.
Affected Version(s)
EasyFlow .NET 6.1.*
EasyFlow .NET 6.6 <= 6.6.19
EasyFlow .NET 8.1 <= 8.1.5
