Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-96429: Flowring Agentflow 4.0 lets attackers run any database command
CVE-2026-96429 · published 3 days ago
Summary
The web interface of Flowring Agentflow 4.0 (versions released before August 8, 2025) lets a remote user send specially crafted data in the 'id' field, causing the system to run unwanted database commands. This can lead to data being read, altered, or deleted without permission. Update to the latest version or apply the vendor's patch to stop the risk.
What to do
- Update flowring technology corp agentflow 4.0 to version 2025/08/08 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| flowring technology corp | agentflow 4.0 | < 2025/08/08 |
Original advisory text
Flowring Agentflow 4.0 - SQL Injection
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API
endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows
remote attackers to execute arbitrary SQL commands via the id parameter.
endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows
remote attackers to execute arbitrary SQL commands via the id parameter.
References
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-89SQL Injection
Timeline
Published29 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Track software like this
Free during beta