CVE-2026-2097Disclosure(flowring / agentflow)

LOWCVSS 8.7 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agentflow

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
agentflow

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-10: 4Technical Details · 2026-02-10: 302-10
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2097 Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby e… https://www.cve.org/CVERecord?id=CVE-2026-2097

    Post summary

    The message announces CVE-2026-2097, describing an arbitrary file upload vulnerability in Agentflow that permits authenticated remote attackers to upload and run web shell backdoors.

    00010344
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2097: HIGH] Arbitrary File Upload vulnerability found in Agentflow by Flowring allows attackers to upload and execute web shells, leading to arbitrary code execution on the server.#cve,CVE-2026-2097,#cybersecurity https://cvefind.com/CVE-2026-2097

    Post summary

    The post announces CVE-2026-2097 as a high‑severity arbitrary file upload flaw in Agentflow by Flowring that can lead to remote code execution via web shells. No PoC, exploit tool, patch, or evidence of active exploitation is mentioned.

    0000065
    583 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-2097 - Flowring - Agentflow - https://www.redpacketsecurity.com/cve-alert-cve-2026-2097-flowring-agentflow/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-2097 #flowring #agentflow

    Post summary

    The post is a brief CVE alert announcing CVE-2026-2097 for Flowring's Agentflow, providing a link to an external advisory but lacking technical or exploit details.

    0000072
    3.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2097 - High Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code e... https://www.thehackerwire.com/vulnerability/CVE-2026-2097/ https://t.co/D1OtpSc7tG

    Post summary

    The post announces CVE-2026-2097, a high‑severity arbitrary file‑upload flaw in Agentflow that permits authenticated remote attackers to upload and execute web shells for arbitrary code execution. No PoC, exploit code, or patch details are provided.

    0000055
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowringagentflow---

Explore more