Description
In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
Published: 2026-07-02
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that an authenticated low-privileged user can send specially crafted requests that trigger unauthorized data access and modification, potentially compromising data integrity and confidentiality. The vulnerability, classified as CWE-89, Detection System (ADS).

Affected Systems

Progress Software Flowmon ADS versions prior to 12.5.6 and 13.0.5 are affected.

Risk and Exploitability

Based on the description, it is inferred that the attack is internal to the ADS. The CVSS score of 8.7 reflects a high severity issue. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV and low-priv internal to the ADS. A determined attacker with a legitimate session can exploit the flaw by sending malicious requests, leading to unauthorized data access and modification. The lack of exploitation does not negate the risk, as the vulnerability can still be leveraged for impactful data tampering.

Generated by OpenCVE AI on July 21, 2026 at 11:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Progress Software Flowmon ADS to version 12.5.6 or 13.0.5 to eliminate the flaw.
  • Restrict low-privileged user permissions so that they cannot access anomaly querying endpoints until the patch is applied.
  • Enable and monitor logging for anomalous request patterns that resemble the crafted inputs, and investigate any incidents promptly.

Generated by OpenCVE AI on July 21, 2026 at 11:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Progress Software
Progress Software flowmon Ads
Vendors & Products Progress Software
Progress Software flowmon Ads

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification.
Title Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Progress Software Flowmon Ads
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-03T03:56:00.966Z

Reserved: 2026-05-22T10:44:21.456Z

Link: CVE-2026-9272

cve-icon Vulnrichment

Updated: 2026-07-02T14:36:31.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')