Progress SoftwareCVE-2026-8079
Progress Software Flowmon: improper authorization
High8.7CVE-2026-8079 · Published Jul 2, 2026 · updated Jul 6, 2026
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Flowmon Product | <= Flowmon 12 versions prior to 12.5.9 | No fix yet |
| <= Flowmon 13 versions prior to 13.0.11 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 8 | Progress Software MOVEit Transfer: improper authorization | Low2.7 | 2025.1.3+1 more |
| Jul 8 | Progress Software MOVEit Transfer: authentication bypass | Low3.7 | 2025.1.3+1 more |
| Jul 8 | Progress Software MOVEit Transfer: cross-site scripting | High8.0 | 2026.0.1+2 more |
| Jul 8 | Progress Software MOVEit Transfer: memory leak | High7.5 | 2025.0.8+2 more |
| Jul 8 | Improper Neutralization of Special Elements in Data Query Logic vulnerability... | High7.2 | 2025.0.8+2 more |
| Jul 2 | Progress Software Flowmon ADS: SQL injection | High8.7 | No fix yet |