Sceawere
Vulnerability Detail
CVE-2026-102457UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
EasyFlow .NET Arbitrary File Read
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- DigiWin
- Product
- EasyFlow .NET
- Attack Type
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T09:17:13.650Z",
"pubdate": "2026-09-30T09:17:13.650Z",
"executiveSummary": "EasyFlow .NET, developed by Digiwin, is susceptible to an Arbitrary File Read vulnerability. This flaw allows an authenticated remote attacker to bypass intended file access restrictions and retrieve sensitive system files from the host server. The vulnerability poses a significant risk to the confidentiality and integrity of the application environment. By exploiting this weakness, an attacker can access configuration files, credentials, source code, or internal system data, potentially facilitating further exploitation or full system compromise. The vulnerability requires the attacker to be authenticated, limiting the immediate exposure to external, unauthenticated threats, yet it remains a critical risk for environments where internal access or low-privileged accounts are compromised. The impact encompasses the unauthorized disclosure of sensitive information which could lead to complete system takeover.",
"technicalDetails": "The Arbitrary File Read vulnerability in EasyFlow .NET originates from improper input validation or insufficient sanitization of user-supplied paths when interacting with the file system. In many .NET web-based applications, this occurs when an application parameter, such as a query string or a form field, is directly utilized as a file path or a directory identifier within server-side file-handling functions without appropriate normalization or validation against a predefined allowlist.\nThe root cause is likely a Path Traversal (CWE-22) issue where the application fails to restrict user input to the intended directory boundaries. An authenticated attacker can manipulate these input parameters by injecting directory traversal sequences such as '../' to escape the designated base directory. By traversing the file system, the attacker can target sensitive files stored outside the web root, such as web.config files containing database connection strings, application configuration settings, or OS-level sensitive files.\nThe attack flow commences with the attacker identifying a vulnerable endpoint within EasyFlow .NET that accepts a file path or name as an argument. The attacker sends a crafted HTTP request to this endpoint containing a manipulated path string. If the application processes this path without verifying that the resulting file remains within the legitimate scope, it will return the requested file content back to the attacker in the HTTP response. The vulnerability essentially turns the application's file retrieval mechanism into an oracle that reads arbitrary files from the server's local file system.\nThis vulnerability is particularly dangerous because it does not necessarily require advanced administrative privileges; standard user credentials may suffice if the application's implementation allows these users to interact with the vulnerable file-reading function. The exposure is limited to the privileges of the service account running the Digiwin EasyFlow .NET application pool. If the application service account is over-privileged, the scope of accessible files expands proportionally. Post-exploitation, the sensitive data harvested from these files can be utilized to perform lateral movement within the network, escalate privileges, or further refine the attack vector against other components of the infrastructure."
}