Impact
The vulnerability is a missing authentication flaw (CWE-306) in DigiWin EasyFlow .NET. Unauthenticated remote attackers can call a specific API and retrieve plaintext passwords of other users, enabling credential theft and potential unauthorized access to user accounts.
Affected Systems
The affected product is DigiWin EasyFlow .NET. Any deployment of this product prior to the patch released after April 17, 2026 may be vulnerable, as no specific version numbers are listed in the advisory.
Risk and Exploitability
The CVSS score of 9.3 indicates a high impact vulnerability. EPSS is not available, and the issue is not listed in CISA KEV, but the lack of authentication provides a straightforward attack vector for remote attackers. An attacker who can reach the vulnerable API can obtain sensitive credentials without any prerequisite, increasing the likelihood of exploitation.
OpenCVE Enrichment