Description
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Progress Flowmon permits an authenticated low‑privileged user to manipulate the PDF generation request so that the system performs operations with the privileges of another account. This unauthorized privilege escalation can lead to sensitive data exposure and unintended modifications to system configuration, thereby compromising confidentiality, integrity, and potentially availability. The flaw arises from a breach of authorization controls, identified as CWE‑863.

Affected Systems

This vulnerability affects Progress Software’s Flowmon product. The CVE does not list specific affected versions, but indicates that any installation where PDF generation is enabled and the product supports user authentication is potentially at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, reflecting a significant impact on the system. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation to date. Exploitation requires an authenticated low‑privileged user, implying that the attack vector likely involves sending a specially crafted PDF generation request from an authenticated session. The rights‑to‑use privilege escalation is limited to contexts where PDF generation is supported and privilege rights are applicable.

Generated by OpenCVE AI on August 3, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Security Update for Progress Flowmon from the vendor’s support portal.
  • Configure PDF generation to be available only to users with elevated privileges using role-based access control.
  • If unable to update immediately, temporarily disable PDF generation until an official fix is applied.

Generated by OpenCVE AI on August 3, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software flowmon
Vendors & Products Progress Software
Progress Software flowmon

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon versions prior to 12.5.9 and 13.0.10, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration. In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon versions prior to 12.5.9 and 13.0.10, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
Title Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Progress Flowmon
Progress Software Flowmon
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-03T03:56:03.186Z

Reserved: 2026-05-07T11:23:34.754Z

Link: CVE-2026-8079

cve-icon Vulnrichment

Updated: 2026-07-02T14:37:19.217Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:11.803

Modified: 2026-07-06T18:43:52.400

Link: CVE-2026-8079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:45:03Z

Weaknesses