Path Traversal Vulnerability in Flowring Agentflow Product by Flowring
CVE-2026-96440
7.1HIGH
What is CVE-2026-96440?
The Flowring Agentflow 4.0 product contains a path traversal vulnerability in the /WebAgenda/download/uploadFile.jsp API endpoint. This flaw allows remote authenticated users to manipulate the path parameter, resulting in unauthorized file writing to locations outside of the designated upload directory. It poses a significant security risk, potentially leading to unauthorized data access and manipulation.
Affected Version(s)
Agentflow 4.0 0 < 2023/03/24
