CVE-2026-39914: Tim Solutions Tim Flow
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.
Affected products
- Tim Solutions Tim Flow: before 26.0.6 (fixed in 26.0.6)
Published 2026-08-24. Last modified 2026-09-24.