CVE-2025-67282
MEDIUMTIM BPM Suite/TIM FLOW <9.1.2 - Privilege Escalation
Title source: llmDescription
In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access work items of other user, modify restricted content in workflows, modify the applications logo and manipulate the profile of other user.
Scores
CVSS v3
5.4
EPSS
0.0001
EPSS Percentile
1.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-288
Status
published
Products (1)
tim-solutions/tim_flow
< 9.1.2
Published
Jan 09, 2026
Tracked Since
Feb 18, 2026