SQL Injection Vulnerability in Flowring Agentflow Software
CVE-2026-96428
9.3CRITICAL
What is CVE-2026-96428?
An SQL Injection vulnerability exists in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 prior to version 2025/08/08. This flaw enables remote attackers to manipulate the SQL queries executed by the application through the words parameter, potentially allowing them to gain unauthorized access to sensitive data or execute arbitrary commands on the database.
Affected Version(s)
Agentflow 4.0 0 < 2025/08/08
