CVE-2026-2096Disclosure(flowring / agentflow)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch flowring agentflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agentflow

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-10); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
agentflow

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-10: 5Mentions · 2026-02-15: 1Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-10: 5Technical Details · 2026-02-15: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 102-1002-1502-2502-26
Signal classification2 categories
Disclosure
787.5%
Patch
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-105
Disclosure5
2026-02-151
Disclosure1
2026-02-251
Disclosure1
2026-02-261
Patch1
Full discourse8 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2096 Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by u… https://www.cve.org/CVERecord?id=CVE-2026-2096

    Post summary

    The post announces a missing authentication vulnerability in Agentflow that permits unauthenticated remote attackers to read, modify, and delete database contents.

    00010370
    56.5K followersView on X
  • mysocAi@MysocAi
    Patch

    [CRITICAL] CVE-2026-2096: Critical Missing Authentication CVE-2026-2096 allows unauthenticated attackers to read, modify, and delete database contents; patch immediately. CVE: CVE-2026-2096 • APT: N/A • Status: ACTIVE … https://www.thehackerwire.com/vulnerability/CVE-2026-2096/

    Post summary

    CVE-2026-2096 is a critical missing authentication flaw that allows unauthenticated attackers to read, modify, and delete database contents; a patch is urgently required.

    000000
    3 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [HIGH] Critical Vulnerability in Agentflow Allows Remote Attacks CVE-2026-2096 enables unauthenticated attackers to read, modify, and delete database contents. CVE: CVE-2026-2096 • APT: N/A • Status: ACTIVE Unauthenti… https://www.thehackerwire.com/vulnerability/CVE-2026-2096/

    Post summary

    A new critical vulnerability (CVE-2026-2096) in Agentflow permits unauthenticated attackers to read, modify, and delete database contents; no PoC, exploit, patch, or active exploitation is reported.

    000001
    3 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2096 (CVSS:9.3, CRITICAL) is Analyzed. Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to..https://nvd.nist.gov/vuln/detail/CVE-2026-2096 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-2096 is a critical missing-authentication vulnerability in Agentflow by Flowring (CVSS 9.3) that permits unauthenticated remote attacks; no PoC, exploit code, or patch details are mentioned.

    0000037
    171 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-2096 är en sårbarhet i Agentflow som tillåter obehöriga att manipulera databasinnehåll utan autentisering. En snabb åtgärd krävs för att skydda kritisk information. #säkerhet #cybersäkerhet #CVE

    Post summary

    The post announces CVE-2026-2096, a critical Agentflow vulnerability that permits unauthenticated database manipulation, urging prompt action to mitigate the risk.

    0000039
    7 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2096: CRITICAL] Flowring's Agentflow software has a critical Missing Authentication flaw, enabling unauthorized remote access for reading, modifying, and deleting database data. #cybersecurity#cve,CVE-2026-2096,#cybersecurity https://cvefind.com/CVE-2026-2096

    Post summary

    The post announces a critical missing authentication flaw in Flowring's Agentflow that permits unauthorized remote access to database data.

    0000069
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-2096 in Flowring Agentflow allows unauthenticated remote attackers to read, modify, & delete DB contents. Immediate attention required! https://radar.offseq.com/threat/cve-2026-2096-cwe-288-authentication-bypass-using--10f90ea1 #OffSeq #Vulnerability #Infosec https://t.co/N8a7D5CbRT

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑2096) in Flowring Agentflow that permits unauthenticated remote attackers to read, modify, and delete database contents, urging immediate attention.

    0000055
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2096 - Critical Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific func... https://www.thehackerwire.com/vulnerability/CVE-2026-2096/ https://t.co/8t2dsD1dol

    Post summary

    A critical Missing Authentication vulnerability in Agentflow by Flowring enables unauthenticated attackers to manipulate database contents, but the tweet provides no PoC, exploit code, or patch information.

    0000064
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowringagentflow---

Explore more