Description
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Published: 2026-09-30
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution via malicious file upload
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an arbitrary file upload flaw that allows privileged remote attackers to place and run web shell backdoors on the server, providing them with the ability to execute arbitrary code.

Affected Systems

The software affected is DigiWin’s EasyFlow .NET. The CVE does not list specific release numbers, but a patch was issued after April 16 2026. Users should verify they are running a version older than the patched release.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and the lack of an EPSS score means the exact exploitation probability is unclear. The vulnerability is not yet in the CISA KEV catalog. Attackers would need remote access to upload files, implying that an exposed web application that allows file uploads could be leveraged. Since the flaw permits execution of arbitrary code, the impact is considerable if exploited.

Generated by OpenCVE AI on September 30, 2026 at 12:04 UTC.

Remediation

Vendor Solution

Update to the patch version released after April 16, 2026.


OpenCVE Recommended Actions

  • Update EasyFlow .NET to the patch version released after April 16 2026.
  • If an immediate update is not possible, disable or heavily restrict the file upload feature, limiting accepted file types and ensuring uploaded content cannot be executed.
  • Monitor the web server for unexpected files or processes that may indicate a web shell has been deployed.

Generated by OpenCVE AI on September 30, 2026 at 12:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Digiwin
Digiwin easyflow .net
Vendors & Products Digiwin
Digiwin easyflow .net

Wed, 30 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Title DigiWin|EasyFlow .NET - Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Digiwin Easyflow .net
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-30T08:26:06.973Z

Reserved: 2026-09-29T08:18:17.165Z

Link: CVE-2026-102454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:13.170

Modified: 2026-09-30T09:17:13.170

Link: CVE-2026-102454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type