In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.
References
| Link | Resource |
|---|---|
| https://community.progress.com/s/article/CVE-2026-3692-Progress-Flowmon | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-02 14:16
Updated : 2026-07-06 18:42
NVD link : CVE-2026-3692
Mitre link : CVE-2026-3692
CVE.ORG link : CVE-2026-3692
JSON object : View
Products Affected
progress
- flowmon
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
