πŸ” CVE Alert

CVE-2026-39914

MEDIUM 6.5

TIM Flow < 26.0.6 Unauthorized SQL Query Execution via Dashboard Export Endpoint

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.

CWE CWE-862
Vendor tim solutions
Product tim flow
Published Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for tim solutions tim flow

Be the first to know when new medium vulnerabilities affecting tim solutions tim flow are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

TIM Solutions / TIM Flow
0 < 26.0.6

References

NVD β†— CVE.org β†— EPSS Data β†—
tim-doc.atlassian.net: https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes vulncheck.com: https://www.vulncheck.com/advisories/tim-flow-unauthorized-sql-query-execution-via-dashboard-export-endpoint

Credits

William VisΓ©e