Cyber & AI intelligence
Wasteland.
Briefs indexed2945
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102458 2026-09-30

Digiwin EasyFlow .NET Flaw Lets Unauthenticated Attackers Retrieve Plaintext Passwords (CVE-2026-102458)

"CVE-2026-102458 is a critical missing-authentication vulnerability in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers obtain other users' plaintext passwords through a specific API."

CVE-2026-102458 is a critical missing-authentication vulnerability in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers obtain other users' plaintext passwords through a specific API.

What Is It

TWCERT/CC reports that EasyFlow .NET, developed by Digiwin, has a missing-authentication vulnerability (CWE-306: Missing Authentication for Critical Function). According to the NVD description, a specific API can be reached without authentication, and it returns other users' passwords in plaintext.

NVD published the record on 2026-09-30. Its status is "Received," so NVD has not yet completed its own analysis.

Why It Matters

TWCERT/CC, the CVE numbering authority, rates the flaw CVSS 3.1 9.8 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It also gives a CVSS 4.0 score of 9.3 (Critical). In practical terms:

An attacker who retrieves other users' plaintext passwords can log in as those users. The CVSS integrity and availability ratings reflect this: the damage goes beyond disclosing the passwords. If users reuse those passwords on other services, the exposure extends beyond EasyFlow .NET.

Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was supplied for this CVE. Active exploitation is not confirmed in the source data, and CVSS 4.0 exploit maturity is listed as "Not Defined."

What's Vulnerable

TWCERT/CC lists the following Digiwin EasyFlow .NET versions as affected:

Branch Affected Versions
6.1 All 6.1.x versions (6.1.*)
6.6 6.6 through 6.6.19
8.1 8.1 through 8.1.5

Versions outside these ranges are marked unaffected by default. NVD has not yet assigned CPE identifiers.

Patch Status

The supplied NVD record does not name fixed versions or a required action. There is no CISA KEV remediation deadline because the CVE has no KEV entry.

Organizations running an affected EasyFlow .NET version should:

Sources