CVE-2026-2514

HIGH

Progress Flowmon ADS < 12.5.5 and < 13.0.3 - Stored Cross-Site Scripting via Malicious Network Data

Title source: llm
STIX 2.1

Description

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.

References (1)

Core 1
Core References

Scores

CVSS v4 8.6
EPSS 0.0019
EPSS Percentile 8.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Published Mar 12, 2026
Tracked Since Mar 12, 2026