What is CVE-2026-47755?
In ITFlow prior to version 26.05, a low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal. Users are urged to upgrade to version 26.05 immediately to mitigate the risk.
Azərbaycanca: ITFlow-da autentifikasiya olunmuş aşağı səlahiyyətli agent digər müştərilərə aid açıq mətn parol və TOTP gizli açarlarını credential redaktə modalını birbaşa sorğulamaqla əldə edə bilər. Versiya 26.05-dən əvvəlki ITFlow istifadəçiləri təsirə məruz qalır, dərhal versiya 26.05-ə yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What sensitive data can a low-privileged authenticated agent retrieve in ITFlow?
A low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the credential edit modal.
What action should be taken to mitigate the CVE-2026-47755 vulnerability?
Users of ITFlow prior to version 26.05 are urged to upgrade to version 26.05 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.