HarborGuard / CVE
Back to search
HIGHCVE-2026-2514Published Modified CNA ProgressSoftware

CVE-2026-2514: Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web application

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.

Metrics

CVSS v4.0
8.6
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Progress Software / Flowmon ADS
    Flowmon ADS 12 versions prior to 12.5.5 · Flowmon ADS 13 versions prior to 13.0.3
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N