Junglewise Threat Intelligence

CVE-2026-52474: AiFlowy arbitrary SpringBean invocation in JobUtil.java

CVE-2026-52474 · Severity: info · Published 2026-07-21

Technologies: AiFlowy. Vendors: AiFlowy.

Executive brief

AiFlowy is a workflow or job management platform. A security flaw in the system's job update component allows remote attackers to trigger unauthorized internal functions. This could lead to the exposure of sensitive configuration data or allow an attacker to gain unauthorized access to the server.

Technical details

A vulnerability exists in the /api/v1/sysJob/update endpoint of AiFlowy versions 2.1.2 and earlier. The root cause is located in JobUtil.java, which fails to properly validate or restrict method calls, allowing for arbitrary SpringBean invocation. A remote attacker can exploit this to execute internal logic, leading to sensitive information disclosure or potential remote code execution (RCE) and server takeover. The attack is reachable over the network via the API.

Affected products

  • AiFlowy AiFlowy <= 2.1.2

Timeline

  • 2026-07-21: disclosed: Initial CVE publication

References

Related threats