CVE-2026-12581: Digiwin Easyflow .net
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
Affected products
- Digiwin Easyflow .net: up to and including 8.1.4
Published 2026-06-22. Last modified 2026-06-22.