Description
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that an authenticated low‑privileged user can send specially crafted requests that trigger unauthorized data, potentially compromising data integrity and confidentiality. The vulnerability, classified as CWE‑89, involves the Anomaly Detection System (ADS).

Affected Systems

Progress Software Flowmon ADS versions prior to 12.5.6 and 13.0.5 are affected.

Risk and Exploitability

Based on the description, it is inferred that the attack is internal to the ADS. The CVSS score of 8.7 reflects a high severity issue. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV. A determined attacker with a legitimate session can exploit the flaw by sending malicious requests, leading to unauthorized data access and modification. The low exploitation likelihood does not negate the risk, as the vulnerability can still be leveraged for impactful data tampering.

Generated by OpenCVE AI on August 3, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Progress Software Flowmon ADS to version 12.5.6 or 13.0.5
  • Enable and monitor logging for anomalous request patterns that resemble the crafted inputs, and investigate any incidents promptly.
  • Restrict anomaly querying endpoints to privileged users only, temporarily disabling them for low‑privileged accounts until the patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software flowmon Ads
Vendors & Products Progress Software
Progress Software flowmon Ads

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
Title Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Progress Flowmon Anomaly Detection System
Progress Software Flowmon Ads
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-03T03:56:00.966Z

Reserved: 2026-05-22T10:44:21.456Z

Link: CVE-2026-9272

cve-icon Vulnrichment

Updated: 2026-07-02T14:36:31.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-02T15:17:11.937

Modified: 2026-07-07T16:37:11.803

Link: CVE-2026-9272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')