Description
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Progress Flowmon permits an authenticated low‑privileged user to manipulate the PDF generation request so that the system performs operations with the privileges of another account. This unauthorized privilege escalation can lead to sensitive data exposure and unintended modifications to system configuration, thereby compromising confidentiality, integrity, and potentially availability. The flaw arises from a breach of authorization controls, identified as CWE‑863.

Affected Systems

This flaw affects Progress Software’s Flowmon product. Versions prior to 12.5.9 in the 12.x release line and prior to 13.0.11 in the 13.x release line are vulnerable. Any deployment of these versions that has PDF generation enabled is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, reflecting a significant impact on the system. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation to date. Exploitation requires an authenticated low‑privileged user, implying that the attack vector likely involves sending a specially crafted PDF generation request from an authenticated session. The rights‑to‑use privilege escalation is limited to contexts where PDF generation is supported and privilege rights are applicable.

Generated by OpenCVE AI on July 21, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Progress Flowmon to version 12.5.9 or later for the12.x line, or 13.0.11 or later for the 13.x line.
  • Limit PDF generation functionality to users with higher privilege levels through role‑based access controls.
  • If an immediate upgrade is not possible, consider disabling PDF generation until a patched version is deployed.

Generated by OpenCVE AI on July 21, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software flowmon
Vendors & Products Progress Software
Progress Software flowmon

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon versions prior to 12.5.9 and 13.0.10, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration. In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon versions prior to 12.5.9 and 13.0.10, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
Title Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Progress Software Flowmon
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-03T03:56:03.186Z

Reserved: 2026-05-07T11:23:34.754Z

Link: CVE-2026-8079

cve-icon Vulnrichment

Updated: 2026-07-02T14:37:19.217Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses