Executive brief
Progress Flowmon, a network monitoring and security analysis solution, is affected by a vulnerability in its report generation process. An attacker with low-level access to the system can send a specially crafted request to execute unauthorized commands on the server. This could lead to a full system takeover, data theft, or disruption of network monitoring operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in Progress Flowmon versions prior to 12.5.8. The flaw is located within the report generation process, where the application fails to properly neutralize special elements in user-supplied requests. An authenticated attacker with low privileges can exploit this by crafting a malicious request that triggers unintended command execution on the underlying server. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the application service. The issue is addressed in Flowmon version 12.5.8.
Affected products
- Progress Software Flowmon 12.x versions prior to 12.5.8
Timeline
- 2026-04-02: advisory: Initial disclosure by Progress Software Corporation
- 2026-04-02: disclosed