Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flowring:agentflow:-:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowring
Flowring agentflow |
|
| Vendors & Products |
Flowring
Flowring agentflow |
Tue, 10 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Flowring|Agentflow - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2026-02-10T07:02:30.835Z
Updated: 2026-02-10T15:39:41.776Z
Reserved: 2026-02-06T11:02:49.215Z
Link: CVE-2026-2097
Updated: 2026-02-10T15:39:36.856Z
Status : Analyzed
Published: 2026-02-10T07:16:14.303
Modified: 2026-02-13T20:51:42.637
Link: CVE-2026-2097
No data.