Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-96429: Flowring Agentflow 4.0 lets attackers run any database command

CVE-2026-96429 · published 3 days ago
Summary

The web interface of Flowring Agentflow 4.0 (versions released before August 8, 2025) lets a remote user send specially crafted data in the 'id' field, causing the system to run unwanted database commands. This can lead to data being read, altered, or deleted without permission. Update to the latest version or apply the vendor's patch to stop the risk.

What to do
  • Update flowring technology corp agentflow 4.0 to version 2025/08/08 or later.
Affected software
VendorProductAffected versions
flowring technology corp agentflow 4.0 < 2025/08/08
Original advisory text
Flowring Agentflow 4.0 - SQL Injection
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API
endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows
remote attackers to execute arbitrary SQL commands via the id parameter.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published29 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-96429 · MITRE
Track software like this
Free during beta