{"id":"CVE-2026-2737","title":"A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…","summary":"A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web sess…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"progress","product":"flowmon","affected":["flowmon >= 12.0.0, < 12.5.8","flowmon >= 13.0.0, < 13.0.6"],"patched":["flowmon 13.0.6"],"published":"2026-04-02","updated":"2026-07-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-2737","references":[{"url":"https://community.progress.com/s/article/CVE-2026-2737-Progress-Flowmon","label":"security@progress.com"}],"tags":["nvd"],"epss":0.00196,"epssPercentile":0.09564,"ingestedAt":"2026-07-06T18:45:21.142Z","slug":"CVE-2026-2737","body":"## Overview\n\nA vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.\n\n## Affected\n\n- `flowmon >= 12.0.0, < 12.5.8`\n- `flowmon >= 13.0.0, < 13.0.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `flowmon 13.0.6`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}