CVE-2026-2514

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-12 13:16

Updated : 2026-03-12 21:07


NVD link : CVE-2026-2514

Mitre link : CVE-2026-2514

CVE.ORG link : CVE-2026-2514


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')