---
id: CVE-2026-2513
title: >-
  A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and
  13.0.3, whereby an administrator who clicks a malicious link provided by an
  attacker may inadvertently trigger unintended actions within their
  authenticated web …
summary: >-
  A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and
  13.0.3, whereby an administrator who clicks a malicious link provided by an
  attacker may inadvertently trigger unintended actions within their
  authenticated web …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: progress
product: flowmon_anomaly_detection_system
affected:
  - 'flowmon_anomaly_detection_system >= 12.0.0, < 12.5.5'
  - 'flowmon_anomaly_detection_system >= 13.0.0, < 13.0.3'
patched:
  - flowmon_anomaly_detection_system 13.0.3
published: '2026-03-12'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2513'
references:
  - url: >-
      https://community.progress.com/s/article/CVE-2026-2513-Progress-Flowmon-ADS
    label: security@progress.com
tags:
  - nvd
epss: 0.00163
epssPercentile: 0.04844
ingestedAt: '2026-09-03T18:06:41.228Z'
---

## Overview

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

## Affected

- `flowmon_anomaly_detection_system >= 12.0.0, < 12.5.5`
- `flowmon_anomaly_detection_system >= 13.0.0, < 13.0.3`

## Remediation

Upgrade past the affected range:

- `flowmon_anomaly_detection_system 13.0.3`
