SQL Injection Vulnerability in ITFlow Documentation and Ticketing System
CVE-2026-54596

8.1HIGH

Key Information:

Vendor

Itflow-org

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54596?

ITFlow, a tool designed for small managed service providers, has a vulnerability allowing SQL injection through the frequency parameter in recurring invoices. This issue affects authenticated users with access to client invoices prior to version 26.07. By exploiting the injection flaw, attackers can manipulate SQL queries through the poorly sanitized input, possibly leading to unauthorized access to sensitive data such as password hashes and SMTP credentials. The vulnerability can further enable attackers to perform updates and modifications within the database and could result in administrative control over the application. This flaw has been addressed in the latest release.

Affected Version(s)

itflow < 26.07

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.