Junglewise Threat Intelligence

CVE-2026-5964: Digiwin EasyFlow .NET SQL injection

CVE-2026-5964 · Severity: critical · CVSS 9.8 · Published 2026-04-20

Technologies: Digiwin Easyflow .Net. Vendors: Digiwin.

Executive brief

Digiwin EasyFlow .NET, an enterprise workflow management system, contains a critical security flaw. An unauthenticated attacker can remotely access the underlying database to view, change, or delete sensitive business information. This could lead to a total loss of data confidentiality and integrity, potentially disrupting business operations and exposing proprietary data.

Technical details

A SQL injection vulnerability (CWE-89) exists in Digiwin EasyFlow .NET due to improper neutralization of special elements in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries. Successful exploitation grants the attacker full access to the database, enabling them to read, modify, or delete any stored data. The vulnerability affects versions V6.1.x, V6.6.x, V8.1.1, and V8.1.2. Users are advised to update to version 8.1.3 or later, or apply the patch released on 2026/01/20.

Affected products

  • Digiwin EasyFlow .NET V6.1.x, V6.6.x, V8.1.1, V8.1.2

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory
  • 2026-01-20: patched: Patch released prior to public advisory

References