Description
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Published: 2026-09-30
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability turns out to be an insecure deserialization flaw that allows unauthenticated remote attackers to execute arbitrary code on the server. Because the deserialization routine accepts crafted data without proper validation, an attacker can inject malicious objects that the framework will instantiate and invoke, effectively running code with the rights of the service process. This weakness directly maps to CWE‑502 and can compromise confidentiality, integrity, and availability of the host system.

Affected Systems

The affected product is DigiWin’s EasyFlow .NET. No specific version information is given in the advisory, so all releases prior to the patch issued after April 16 2026 should be considered vulnerable and must be updated.

Risk and Exploitability

The assessed CVSS score of 9.3 indicates an extremely high severity. The advisory does not provide an EPSS value, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by sending a specially crafted serialized payload over the network, so the likely attack vector is remote. Successful exploitation would grant the attacker full control of the target machine.

Generated by OpenCVE AI on September 30, 2026 at 12:18 UTC.

Remediation

Vendor Solution

Update to the patch version released after April 16, 2026.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch released after April 16 2026 to all instances of EasyFlow .NET.
  • Restrict network access to the application by limiting inbound traffic to trusted IPs or enforcing VPN or firewall rules so that only authorized users can reach the deserialization endpoint.
  • After patching, review and disable any legacy deserialization code paths or sanitize existing serialized data to prevent accidental reuse of the vulnerability.

Generated by OpenCVE AI on September 30, 2026 at 12:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Digiwin
Digiwin easyflow .net
Vendors & Products Digiwin
Digiwin easyflow .net

Wed, 30 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title DigiWin|EasyFlow - Insecure Deserialization DigiWin|EasyFlow .NET - Insecure Deserialization

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
Title DigiWin|EasyFlow - Insecure Deserialization
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Digiwin Easyflow .net
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-30T09:29:59.076Z

Reserved: 2026-09-29T08:18:18.287Z

Link: CVE-2026-102455

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:13.343

Modified: 2026-09-30T09:17:13.343

Link: CVE-2026-102455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:30:17Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data