CVE-2026-2097
8.8Flowring · Agentflow
Flowring Agentflow contains an arbitrary file upload vulnerability that allows authenticated remote attackers to execute malicious code on the server via web shell backdoors.
Executive summary
A critical arbitrary file upload vulnerability in Flowring Agentflow allows authenticated attackers to achieve remote code execution.
Vulnerability
This vulnerability is an unrestricted upload of a file with a dangerous type (CWE-434). It allows an authenticated remote attacker to upload and execute web shell backdoors on the server, resulting in arbitrary code execution.
Business impact
The ability for an attacker to execute arbitrary code provides full control over the affected server, leading to potential data exfiltration, system compromise, and lateral movement within the network. With a CVSS score of 8.8, this high-severity vulnerability represents a significant risk to operational integrity and security, as it allows attackers to bypass standard application controls once they have authenticated access.
Remediation
Immediate Action: Contact the vendor, Flowring, to obtain the latest security patches or configuration hardening guides for the Agentflow platform.
Proactive Monitoring: Review web server access logs for unusual file upload activity or requests to unknown files within the application directories.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to restrict file uploads to authorized file types and scan all incoming file streams for malicious signatures.
Exploitation status
Public Exploit Available: No confirmed public exploit (exploit_available: false).
Analyst recommendation
Given the high severity of this remote code execution flaw, organizations using Flowring Agentflow should treat this as a priority item. Administrators must verify their current version status with the vendor and apply recommended updates immediately. While no exploit is currently observed in the wild, the potential for total system compromise necessitates swift defensive action.