CVE-2026-102457: Digiwin Easyflow .net

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.

Affected products

  • Digiwin Easyflow .net: from 6.1, before 6.2 (fixed in 6.2); from 6.6, up to and including 6.6.19; from 8.1, up to and including 8.1.5

Published 2026-09-30. Last modified 2026-09-30.