Home

Description

In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context.

PUBLISHED Reserved 2026-02-14 | Published 2026-03-12 | Updated 2026-03-13 | Assigner ProgressSoftware




HIGH: 8.6CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
affected

Flowmon ADS 12 versions prior to 12.5.5 (custom)
affected

Flowmon ADS 13 versions prior to 13.0.3 (custom)
affected

References

community.progress.com/...CVE-2026-2514-Progress-Flowmon-ADS vendor-advisory

cve.org (CVE-2026-2514)

nvd.nist.gov (CVE-2026-2514)

Download JSON