EasyFlow .NET Session Fixation Enables Privilege Escalation
CVE-2026-12581 Published on June 22, 2026
Digiwin|EasyFlow .NET - Session Fixation
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
Vulnerability Analysis
CVE-2026-12581 can be exploited with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Affected Versions
Digiwin EasyFlow .NET:- Before and including 8.1.4 is affected.