CVE-2026-12581: Digiwin Easyflow .net

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

Affected products

  • Digiwin Easyflow .net: up to and including 8.1.4

Published 2026-06-22. Last modified 2026-06-22.