Junglewise Threat Intelligence

CVE-2026-9272: Progress Flowmon ADS SQL injection in Anomaly Detection System

CVE-2026-9272 · Severity: info · CVSS 8.7 · Published 2026-07-02

Vendors: Progress Software.

Executive brief

Progress Flowmon ADS, a network security tool used for anomaly detection and traffic analysis, is affected by a security vulnerability. An attacker with low-level user access can send malicious requests to the system to view or change sensitive application data. This could allow an unauthorized user to tamper with security logs or access confidential network monitoring information.

Technical details

An SQL injection vulnerability (CWE-89) exists in Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5. The flaw is located within the Anomaly Detection System (ADS) component, where the application fails to properly neutralize special elements in SQL commands. An attacker authenticated as a low-privileged user can exploit this by sending specially crafted network requests. Successful exploitation allows for unauthorized access to the underlying database, enabling the attacker to read, modify, or delete application data. Progress has released patches in versions 12.5.6 and 13.0.5 to address this issue.

Affected products

  • Progress Software Flowmon ADS 12 prior to 12.5.6
  • Progress Software Flowmon ADS 13 prior to 13.0.5

Timeline

  • 2026-07-02: advisory: Initial advisory published by Progress Software and NVD.
  • 2026-07-02: patched: Fixes available in versions 12.5.6 and 13.0.5.

References