Executive brief
Progress Flowmon is a network monitoring and security analysis solution. A vulnerability in its PDF generation process allows a logged-in user with low privileges to perform actions as if they were a different user. This could allow an attacker to access sensitive data they are not authorized to see or make unauthorized changes to the system's configuration.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Progress Flowmon's PDF generation component. An authenticated, low-privileged attacker can craft a malicious request during the report generation process to trigger operations with the privileges of another user. This privilege escalation can be leveraged to access sensitive data or modify system configurations. The vulnerability affects Flowmon versions prior to 12.5.9 and 13.0.11. Users are advised to upgrade to the patched versions to mitigate this risk.
Affected products
- Progress Software Corporation Flowmon 12.x versions prior to 12.5.9, 13.x versions prior to 13.0.11
Timeline
- 2026-07-02: advisory: Initial disclosure by Progress Software Corporation