CVE-2026-96431EPSS p18.1%
CVE-2026-96431CVE-2026-96431
Description
Unrestricted Upload of File with Dangerous Type in the
/WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version
before 2023/03/24 allows remote authenticated users to execute arbitrary
system commands via a malicious file.
Scoring
| EPSS | 0.27% probability of exploitation · percentile 18.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-29 |