SQL Injection Vulnerability in Flowring Agentflow Software
CVE-2026-96428

9.3CRITICAL

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-96428?

An SQL Injection vulnerability exists in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 prior to version 2025/08/08. This flaw enables remote attackers to manipulate the SQL queries executed by the application through the words parameter, potentially allowing them to gain unauthorized access to sensitive data or execute arbitrary commands on the database.

Affected Version(s)

Agentflow 4.0 0 < 2025/08/08

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.