Improper Authorization Vulnerability in TIM Flow by TIM Group
CVE-2026-39914
7.1HIGH
What is CVE-2026-39914?
TIM Flow versions prior to 26.0.6 exhibit an improper authorization vulnerability. This issue allows authenticated users to exploit a privileged dashboard export endpoint intended solely for administrative access. By crafting specific SQL queries, these users can bypass role-based access controls and retrieve sensitive database information as a downloadable spreadsheet. This vulnerability poses a significant risk, as it exposes internal data and compromises the integrity of the system.
Affected Version(s)
TIM Flow 0
