CVE-2026-12581

HIGH

Digiwin|EasyFlow .NET - Session Fixation

Title source: cna
STIX 2.1

Description

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10980-0e640-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-10981-8617d-2.html

Scores

CVSS v3 7.5
EPSS 0.0045
EPSS Percentile 37.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-384
Status published
Products (1)
Digiwin/EasyFlow .NET < 8.1.4
Published Jun 22, 2026
Tracked Since Jun 22, 2026