Executive brief
EasyFlow .NET, a business process management and workflow solution, contains a critical security flaw. An unauthenticated attacker can remotely access the underlying database to view, change, or delete sensitive corporate data. This could lead to a total compromise of the system's information integrity and confidentiality.
Technical details
A SQL injection vulnerability (CWE-89) exists in Digiwin EasyFlow .NET due to improper neutralization of special elements used in SQL commands. The flaw is reachable over the network without authentication (AV:N/PR:N). An attacker can exploit this by sending crafted SQL queries to the application, enabling full access to the backend database. This allows for unauthorized data exfiltration, modification, or deletion. The vulnerability affects versions 6.1.x, 6.6.x, and 8.1.1 through 8.1.4, and is resolved in version 8.1.5 or by applying the January 2026 patch.
Affected products
- Digiwin EasyFlow .NET 6.1.x, 6.6.x, 8.1.1, 8.1.2, 8.1.3, 8.1.4
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory
- 2026-01-20: patched: Patch released prior to public disclosure