CVE-2026-102454 PUBLISHED

DigiWin|EasyFlow .NET - Arbitrary File Upload

Assigner: twcert
Reserved: 29.09.2026 Published: 30.09.2026 Updated: 30.09.2026

EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor DigiWin
Product EasyFlow .NET
Versions Default: unaffected
  • Version 6.1.* is affected
  • affected from 6.6 to 6.6.19 (incl.)
  • affected from 8.1 to 8.1.5 (incl.)

Solutions

Update to the patch version released after April 16, 2026.

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE