CVE-2026-2514

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:flowmon_anomaly_detection_system:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:flowmon_anomaly_detection_system:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-12 13:16

Updated : 2026-09-03 17:34


NVD link : CVE-2026-2514

Mitre link : CVE-2026-2514

CVE.ORG link : CVE-2026-2514


JSON object : View

Products Affected

progress

  • flowmon_anomaly_detection_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')