CVE-2026-102458 is a critical missing-authentication vulnerability in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers obtain other users' plaintext passwords through a specific API.
What Is It
TWCERT/CC reports that EasyFlow .NET, developed by Digiwin, has a missing-authentication vulnerability (CWE-306: Missing Authentication for Critical Function). According to the NVD description, a specific API can be reached without authentication, and it returns other users' passwords in plaintext.
NVD published the record on 2026-09-30. Its status is "Received," so NVD has not yet completed its own analysis.
Why It Matters
TWCERT/CC, the CVE numbering authority, rates the flaw CVSS 3.1 9.8 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It also gives a CVSS 4.0 score of 9.3 (Critical). In practical terms:
- Attack vector: Network
- Attack complexity: Low
- Privileges required: None
- User interaction: None
- Impact: High confidentiality, integrity and availability impact on the vulnerable system
An attacker who retrieves other users' plaintext passwords can log in as those users. The CVSS integrity and availability ratings reflect this: the damage goes beyond disclosing the passwords. If users reuse those passwords on other services, the exposure extends beyond EasyFlow .NET.
Exploitation status: No CISA Known Exploited Vulnerabilities (KEV) entry was supplied for this CVE. Active exploitation is not confirmed in the source data, and CVSS 4.0 exploit maturity is listed as "Not Defined."
What's Vulnerable
TWCERT/CC lists the following Digiwin EasyFlow .NET versions as affected:
| Branch | Affected Versions |
|---|---|
| 6.1 | All 6.1.x versions (6.1.*) |
| 6.6 | 6.6 through 6.6.19 |
| 8.1 | 8.1 through 8.1.5 |
Versions outside these ranges are marked unaffected by default. NVD has not yet assigned CPE identifiers.
Patch Status
The supplied NVD record does not name fixed versions or a required action. There is no CISA KEV remediation deadline because the CVE has no KEV entry.
Organizations running an affected EasyFlow .NET version should:
- Read the TWCERT/CC advisories linked below for vendor remediation guidance.
- Contact Digiwin to confirm which versions are fixed.
- Because the flaw exposes plaintext credentials, consider resetting the passwords of EasyFlow .NET users on affected systems once a fix is applied.