Status: UPDATED | Advisory ID: CVE-2026-3692
| CVE | CVE-2026-3692 |
| CVSS | CVSS 8.8 (High). |
| Affected products | Progress flowmon |
| Classified as | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-3692 |
| Vendor advisory | https://community.progress.com/s/article/CVE-2026-3692-Progress-Flowmon |