Back to all
2026-09-29

Flowring Agentflow 4.0 - Exposed Dangerous Method or Function

ZUSOART ID
ZA-2026-11
CVE ID
CVE-2026-96430
Vulnerability Type
CWE-749: Exposed Dangerous Method or Function
CVSS 4.0 Base
8.7
Description

Exposed  Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of  Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated  users to execute arbitrary SQL commands via the sql parameter.

‍

Vendor
Flowring Technology Corp
Product
Category
Version affected
Agentflow 4.0
Before 2026/08/28
Mitigations

Update Agentflow 4.0 to 2026/08/28.

‍

Release date
2026-09-29
Credit

Kuang Ming Chang of ZUSO ART