{"id":"CVE-2026-2513","title":"A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …","summary":"A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web …","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"progress","product":"flowmon_anomaly_detection_system","affected":["flowmon_anomaly_detection_system >= 12.0.0, < 12.5.5","flowmon_anomaly_detection_system >= 13.0.0, < 13.0.3"],"patched":["flowmon_anomaly_detection_system 13.0.3"],"published":"2026-03-12","updated":"2026-09-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-2513","references":[{"url":"https://community.progress.com/s/article/CVE-2026-2513-Progress-Flowmon-ADS","label":"security@progress.com"}],"tags":["nvd"],"epss":0.00163,"epssPercentile":0.05937,"ingestedAt":"2026-09-03T18:06:41.228Z","slug":"CVE-2026-2513","body":"## Overview\n\nA vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.\n\n## Affected\n\n- `flowmon_anomaly_detection_system >= 12.0.0, < 12.5.5`\n- `flowmon_anomaly_detection_system >= 13.0.0, < 13.0.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `flowmon_anomaly_detection_system 13.0.3`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}