Skip to content
Progress SoftwareCVE-2026-9272

Progress Software Flowmon ADS: SQL injection

High8.7CVE-2026-9272 · Published Jul 2, 2026 · updated Jul 7, 2026

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.

Progress Software advisory

Affected versions

PackageAffectedFixed in
Flowmon ADS
Product
<= Flowmon ADS 12 versions prior to 12.5.6No fix yet
<= Flowmon ADS 13 versions prior to 13.0.5No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-89

More Progress Software advisories

All Progress Software
Advisory
Progress Software MOVEit Transfer: improper authorization
Low2.7Jul 8
Progress Software MOVEit Transfer: authentication bypass
Low3.7Jul 8
Progress Software MOVEit Transfer: cross-site scripting
High8.0Jul 8
Progress Software MOVEit Transfer: memory leak
High7.5Jul 8
Improper Neutralization of Special Elements in Data Query Logic vulnerability...
High7.2Jul 8
Progress Software Flowmon: improper authorization
High8.7Jul 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.