Session Fixation Vulnerability in EasyFlow .NET by Digiwin
CVE-2026-12581
7.7HIGH
What is CVE-2026-12581?
The EasyFlow .NET application developed by Digiwin is vulnerable to session fixation attacks. This vulnerability allows unauthenticated remote attackers to forcibly set a session ID for a legitimate user. Once the user logs in with the manipulated session ID, the attacker gains unauthorized access to the user's privileges, potentially leading to further exploitation and data breach.
Affected Version(s)
EasyFlow .NET 0 <= 8.1.4
