Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns
EditorialBy TrustList Editorial
TWCERT/CC warned on 30 September 2026 of six flaws in Digiwin’s EasyFlow .NET workflow software. Two are critical (CVSS 9.8): unauthenticated code execution and theft of users’ plaintext passwords. Patch to the vendor’s latest build.
- Taiwan
- Taipei, Taiwan
- Cybersecurity
- Business Process Management Software
- +2 more
About Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns
Digiwin EasyFlow .NET has critical flaws allowing unauthenticated code execution and password theft, Taiwan’s CERT warns
30 September 2026 — Taiwan's computer emergency response team, TWCERT/CC, published two vulnerability notes on 30 September 2026 for EasyFlow .NET. EasyFlow .NET is the electronic workflow and approval system from Digiwin (鼎新數智), widely used by Taiwanese and Chinese manufacturers and service firms alongside Digiwin's ERP. The notes cover six vulnerabilities. Two are rated critical at 9.8 under CVSS 3.1, and both can be exploited without logging in.
The vulnerabilities
- CVE-2026-102455, insecure deserialisation (9.8, critical): an unauthenticated remote attacker can execute arbitrary code on the server.
- CVE-2026-102458, missing authentication (9.8, critical): an unauthenticated attacker can obtain other users' passwords in plain text through a specific API.
- CVE-2026-102456, SQL injection (6.5): requires authentication.
- CVE-2026-102457, arbitrary file read (6.5): requires authentication.
- CVE-2026-102459, reflected cross-site scripting (6.1).
- CVE-2026-102454, arbitrary file upload (7.2, high): an attacker who already has administrator rights can upload and run a web shell.
Affected versions and fixes
TWCERT/CC lists EasyFlow .NET V6.1.x and earlier, V6.6.19 and earlier, and V8.1.5 and earlier as affected. The fix for each flaw is to update to a patch released after a given date:
- CVE-2026-102455 and CVE-2026-102454: after 16 April 2026;
- CVE-2026-102458: after 17 April 2026;
- CVE-2026-102457: after 20 April 2026;
- CVE-2026-102456 and CVE-2026-102459: after 26 June 2026.
A system patched to a build later than 26 June 2026 is therefore covered for all six. The notes do not report exploitation.
Why it matters
Workflow systems hold approval chains for purchasing, expenses and HR, and often sit next to the ERP with privileged connections to it. Plaintext passwords taken from EasyFlow can be reused against other systems if staff share passwords. Code execution on the server can be a step into the wider network.
What to do
- Check the patch level of every EasyFlow .NET installation, and apply Digiwin's latest patch if it predates 26 June 2026.
- Do not expose EasyFlow directly to the internet; put it behind a VPN or reverse proxy with authentication.
- If a server was unpatched and internet-facing, reset EasyFlow user passwords and check for unfamiliar files in the web directories.
- Digiwin partners and resellers should contact customers on older versions.
Sources
Categories & features
- Taiwan
- Taipei, Taiwan
- Cybersecurity
- Business Process Management Software
- Workflow Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.