Junglewise Threat Intelligence

CVE-2026-39914: TIM Flow unauthorized SQL query execution via dashboard export

CVE-2026-39914 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Executive brief

TIM Flow is a workflow/dashboard management tool used by organizations to analyze and export business data. An authentication flaw allows any logged-in user to bypass administrative access controls and submit custom SQL queries to generate downloadable Excel spreadsheets containing any database information—enabling unauthorized data theft without needing admin privileges.

Technical details

TIM Flow before 26.0.6 contains an improper authorization vulnerability (CWE-862) in the dashboard Excel export endpoint. The vulnerability allows any authenticated user to submit arbitrary SQL queries to an endpoint intended only for administrators. The attack requires prior authentication but no other preconditions; an attacker with valid credentials can craft malicious SQL queries and retrieve sensitive database contents as downloadable spreadsheets, completely bypassing role-based access controls. The vulnerability is addressed in version 26.0.6 and later.

Affected products

  • TIM TIM Flow before 26.0.6

Timeline

  • 2026-08-24: disclosed

References