← All Advisories

CVE-2026-3692

Status: UPDATED  |  Advisory ID: CVE-2026-3692

Key Details

CVECVE-2026-3692
CVSSCVSS 8.8 (High).
Affected productsProgress flowmon
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-3692
Vendor advisoryhttps://community.progress.com/s/article/CVE-2026-3692-Progress-Flowmon