TopVuln

High-risk vulnerability digests

CVE-2026-5964

  • CRITICAL

Details

CVSS v3
9.8
CVSS v4
9.3
NVD published
2026-04-20 08:16:10
EPSS
0.1% probability · 28.3th percentile — 2026-05-12
Affected versions
Digiwin EasyFlow .NET
Summary
This critical vulnerability is an unauthenticated SQL injection flaw in Digiwin's EasyFlow .NET enterprise workflow platform. Unauthenticated remote attackers can inject arbitrary SQL commands without prior authentication to the application. Attackers can read, modify, or delete all contents of the application's backend database, leading to full data compromise.
Remediation
Apply the official vendor patch for this vulnerability as soon as it is released. Deploy web application firewall rules to block malicious SQL injection attempts targeting EasyFlow .NET instances. Restrict the permissions of the application's database user to limit the impact of potential exploitation.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.