---
id: CVE-2026-2737
title: >-
  A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and
  13.0.6, whereby an administrator who clicks a malicious link provided by an
  attacker may inadvertently trigger unintended actions within their
  authenticated web sess…
summary: >-
  A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and
  13.0.6, whereby an administrator who clicks a malicious link provided by an
  attacker may inadvertently trigger unintended actions within their
  authenticated web sess…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: progress
product: flowmon
affected:
  - 'flowmon >= 12.0.0, < 12.5.8'
  - 'flowmon >= 13.0.0, < 13.0.6'
patched:
  - flowmon 13.0.6
published: '2026-04-02'
updated: '2026-07-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-2737'
references:
  - url: 'https://community.progress.com/s/article/CVE-2026-2737-Progress-Flowmon'
    label: security@progress.com
tags:
  - nvd
epss: 0.00196
epssPercentile: 0.09579
ingestedAt: '2026-07-06T18:45:21.142Z'
---

## Overview

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

## Affected

- `flowmon >= 12.0.0, < 12.5.8`
- `flowmon >= 13.0.0, < 13.0.6`

## Remediation

Upgrade past the affected range:

- `flowmon 13.0.6`
