---
id: CVE-2026-39914
title: >-
  TIM Flow before 26.0.6 contains an improper authorization vulnerability that
  allows any authenticated user to submit arbitrary SQL queries to a privileged
  dashboard Excel export endpoint intended for administrative use only
summary: >-
  TIM Flow before 26.0.6 contains an improper authorization vulnerability that
  allows any authenticated user to submit arbitrary SQL queries to a privileged
  dashboard Excel export endpoint intended for administrative use only.
  Attackers ca…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
published: '2026-08-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:43:32.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-39914'
references:
  - url: >-
      https://tim-doc.atlassian.net/wiki/spaces/eng/pages/230981636/Release+Notes
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tim-flow-unauthorized-sql-query-execution-via-dashboard-export-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00375
epssPercentile: 0.28785
ingestedAt: '2026-09-24T20:51:40.222Z'
---

## Overview

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
