Junglewise Threat Intelligence

CVE-2026-75415: AntFlow authentication bypass via header forgery in request logging filter

CVE-2026-75415 · Severity: high · CVSS 7.5 · Published 2026-08-26

Executive brief

AntFlow is a workflow automation and process management platform. An authentication bypass vulnerability in the request logging filter allows attackers to forge user identities by manipulating the request header, enabling unauthorized access to sensitive process monitoring information and other protected data without valid credentials.

Technical details

AntFlow V2.0.0 contains an authentication bypass vulnerability in the JiMuMDCCommonsRequestLoggingFilter.java component, which retrieves the userid directly from the HTTP request header without proper validation. This header-based identity verification is trivial to forge, allowing unauthenticated attackers to impersonate any user and access restricted functionality. An attacker can craft requests with arbitrary userid headers to bypass authentication entirely and retrieve sensitive information such as process monitoring details. The vulnerability requires only network access to the AntFlow application and no additional prerequisites; exploitation is straightforward and trivial. Patches or workarounds have not been confirmed as of the advisory publication date.

Affected products

  • AntFlow AntFlow V2.0.0

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: advisory: CVE-2026-75415 published

References

Related threats