CVE-2026-2097 PUBLISHED

Flowring|Agentflow - Arbitrary File Upload

Assigner: twcert
Reserved: 06.02.2026 Published: 10.02.2026 Updated: 10.02.2026

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Flowring
Product Agentflow
Versions Default: unaffected
  • Version 0 is affected

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server