Improper Input Validation in ITFlow Email Parser
CVE-2026-97735

8HIGH

Key Information:

Vendor

Itflow

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-97735?

The ITFlow application prior to version 26.08 permits arbitrary SVG file attachments in the ticket email parser. This vulnerability occurs when email messages, sent via SMTP from any source, are processed by the system, allowing potential malicious payloads to be executed. This poses a risk as it opens pathways for attacks leveraging SVG files, which could lead to further exploitation of the application or the server hosting it.

Affected Version(s)

ITFlow 0 < 26.08

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.