CVE-2026-8079 Details
Description
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
A vulnerability exists in Progress Flowmon versions prior to 12.5.9 and 13.0.11, allowing an authenticated low-privileged user to manipulate requests during the PDF generation process. This exploitation can result in actions being executed with the privileges of another user, potentially causing unauthorized access to sensitive information and unintended alterations to system settings.
Users are advised to upgrade to Progress Flowmon versions 12.5.9 or 13.0.10. Upgrade packages are available through the Progress Community or the Progress Update Catalog. Note that the upgrade process will cause a system outage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://community.progress.com/s/article/Flowmon-CVE-2026-8079 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| progress flowmon | >= 12.0.0, < 12.5.9 >= 13.0.0, < 13.0.11 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | Initial Analysis | [email protected] |
| Jul 3, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | [email protected] |
| Jul 2, 2026 | CVE Modified | CISA-ADP |