Skip to content
TrustList
News

Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns

Editorial

By TrustList Editorial

TWCERT/CC warned on 30 September 2026 of six flaws in Digiwin’s EasyFlow .NET workflow software. Two are critical (CVSS 9.8): unauthenticated code execution and theft of users’ plaintext passwords. Patch to the vendor’s latest build.

About Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns

Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns

30 September 2026 — Taiwan's computer emergency response team, TWCERT/CC, published two vulnerability notes on 30 September 2026 for EasyFlow .NET. EasyFlow .NET is the electronic workflow and approval system from Digiwin (鼎新數智), widely used by Taiwanese and Chinese manufacturers and service firms alongside Digiwin's ERP. The notes cover six vulnerabilities. Two are rated critical at 9.8 under CVSS 3.1, and both can be exploited without logging in.

The vulnerabilities

  • CVE-2026-102455, insecure deserialisation (9.8, critical): an unauthenticated remote attacker can execute arbitrary code on the server.
  • CVE-2026-102458, missing authentication (9.8, critical): an unauthenticated attacker can obtain other users' passwords in plain text through a specific API.
  • CVE-2026-102456, SQL injection (6.5): requires authentication.
  • CVE-2026-102457, arbitrary file read (6.5): requires authentication.
  • CVE-2026-102459, reflected cross-site scripting (6.1).
  • CVE-2026-102454, arbitrary file upload (7.2, high): an attacker who already has administrator rights can upload and run a web shell.

Affected versions and fixes

TWCERT/CC lists EasyFlow .NET V6.1.x and earlier, V6.6.19 and earlier, and V8.1.5 and earlier as affected. The fix for each flaw is to update to a patch released after a given date:

  • CVE-2026-102455 and CVE-2026-102454: after 16 April 2026;
  • CVE-2026-102458: after 17 April 2026;
  • CVE-2026-102457: after 20 April 2026;
  • CVE-2026-102456 and CVE-2026-102459: after 26 June 2026.

A system patched to a build later than 26 June 2026 is therefore covered for all six. The notes do not report exploitation.

Why it matters

Workflow systems hold approval chains for purchasing, expenses and HR, and often sit next to the ERP with privileged connections to it. Plaintext passwords taken from EasyFlow can be reused against other systems if staff share passwords. Code execution on the server can be a step into the wider network.

What to do

  • Check the patch level of every EasyFlow .NET installation, and apply Digiwin's latest patch if it predates 26 June 2026.
  • Do not expose EasyFlow directly to the internet; put it behind a VPN or reverse proxy with authentication.
  • If a server was unpatched and internet-facing, reset EasyFlow user passwords and check for unfamiliar files in the web directories.
  • Digiwin partners and resellers should contact customers on older versions.

Sources

Categories & features