{"id":"CVE-2026-39914","title":"TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only","summary":"TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers ca…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-862"],"published":"2026-08-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:43:32.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-39914","references":[{"url":"https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tim-flow-unauthorized-sql-query-execution-via-dashboard-export-endpoint","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00375,"epssPercentile":0.28785,"ingestedAt":"2026-09-24T20:51:40.222Z","slug":"CVE-2026-39914","body":"## Overview\n\nTIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}