External risk intelligence

Flowring Agentflow SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96429

The vulnerability exists in an API endpoint (/WebAgenda/SMBAjaxConfigProcess.do) of a web-based application. Such web application endpoints are commonly deployed as internet-facing services to facilitate remote access or web-based management, making public exposure a common deployment pattern for this type of product role.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a web application's API, specifically within the Flowring Agentflow product. This issue allows for unauthorized execution of commands by remote attackers through a common parameter in the `/WebAgenda/SMBAjaxConfigProcess.do` endpoint, potentially impacting systems that use this technology.

  • Remote attackers can execute commands via a web API.
  • It affects a widely accessible web application feature.
  • Confirm if your business uses this specific web application.

Attack Path

How an attacker could exploit the issue

Attackers can reach an API endpoint exposed online and send specially crafted requests to the server. The vulnerability lies within an API designed to process agenda configurations, and a flaw in how it handles a parameter allows an attacker to inject malicious SQL commands. This can potentially lead to the execution of arbitrary SQL, impacting the confidentiality, integrity, and availability of the system.

  • Entry condition: Publicly accessible API endpoint.
  • Trigger point: Specially crafted `id` parameter.
  • Resulting risk: Arbitrary SQL command execution.

Live Threat

Current exploitation, exposure, and threat context

This SQL injection vulnerability in the API endpoint could allow attackers to execute arbitrary SQL commands. This could potentially impact the integrity and availability of the system's data.

  • System data integrity may be affected.
  • Remote attackers could inject SQL commands.
  • Service availability could be impacted.

Operational Fix

Recommended remediation, mitigation, and detection steps

This SQL injection vulnerability in the Flowring Agentflow API requires action from application owners and infrastructure teams responsible for its deployment. The initial focus should be on discovering all instances of the affected technology, assessing their exposure and business criticality, and identifying the precise system owner to coordinate remediation efforts.

  • Confirm system ownership and exposure.
  • Identify reachable and critical instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Flowring Agentflow?

Flowring Agentflow is a business process management and workflow automation platform. Organizations use it to digitize and manage complex internal operations, forms, and enterprise tasks. Because it serves as a central hub for organizational workflows, it often includes web-based components that allow users and services to interact with its data and configuration settings remotely.

How does CVE-2026-96429 work?

This vulnerability is an instance of CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. In plain English, the application fails to properly sanitize user-provided data before including it in a database query. By sending a specifically formatted 'id' parameter to the affected API, an attacker can trick the system into executing unauthorized SQL commands, potentially viewing or altering backend database information.

What triggers this SQL injection?

The flaw is triggered when the application processes a malformed 'id' parameter sent to the /WebAgenda/SMBAjaxConfigProcess.do API endpoint. Requests that do not interact with this specific parameter or this exact endpoint do not trigger the bug. Essentially, the vulnerability is confined to how the system handles input specifically within this configuration processing component.

Do I need to worry if my instance is internal?

Halo Surface Signal notes that this specific API endpoint is frequently deployed as an internet-facing service to support remote access. While an internet-facing configuration significantly increases the potential for unauthorized access, any instance running the affected version remains vulnerable. If your deployment is internal-only, the risk is lower but not eliminated, as an attacker with initial access to your network could still reach the endpoint.

How should I respond to this threat?

Your first step is to perform an inventory to locate all active instances of Flowring Agentflow within your environment. Once you have identified these systems, prioritize them based on their business criticality and network accessibility. Coordinate with your infrastructure and application teams to confirm the specific version in use and plan for remediation steps as they become available for your environment.

References