CVE-2022-39038

HIGH

Agentflow BPM - Privilege Escalation

Title source: llm
STIX 2.1

Description

Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change the name of the user account to acquire arbitrary account privilege, and access, manipulate system or disrupt service.

Scores

CVSS v3 8.8
EPSS 0.0085
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
flowring/agentflow 4.0.0.1183.552
Published Nov 10, 2022
Tracked Since Feb 18, 2026