Vulnerability Intelligence Report
Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon
CVE-2026-8079
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-863 ↗CWE-863 Incorrect Authorization
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Progress Software | Flowmon | Flowmon 12 versions prior to 12.5.9 (affected), Flowmon 13 versions prior to 13.0.11 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Progress Software Corporation · Vendor · USA |
| Reserved | 2026-05-07T11:23:34 |
| Published | 2026-07-02T14:03:36 |
| Last Updated | 2026-07-03T03:56:03 |
Community Chatter & Buzz