CVE-2026-39914: Missing Authorization in TIM Solutions TIM Flow
Description
TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint intended for administrative use only. Attackers can craft and submit unauthorized SQL queries to the export endpoint to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls.
CVSS v4.0
Score 7.1high
Affected software
TIM Solutions
TIM Flow
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-39914 is an improper authorization vulnerability in TIM Flow before version 26.0.6. Authenticated users can submit arbitrary SQL queries to an administrative dashboard export endpoint, which is intended only for privileged users. This allows attackers to bypass role-based access controls and extract sensitive database information by downloading it as Excel spreadsheets.
Potential Impact
An attacker with any authenticated access can retrieve sensitive database contents without proper authorization by exploiting the vulnerable export endpoint. This leads to unauthorized data disclosure and potential compromise of confidential information.
Mitigation Recommendations
A fix is available in TIM Flow version 26.0.6. Users should upgrade to version 26.0.6 or later to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-04-07T20:57:06.209Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8c53b1acd9273b49a6bf03
Added to database: 08/24/2026, 14:22:41 UTC
Last enriched: 10/02/2026, 15:49:45 UTC
Last updated: 10/08/2026, 06:48:16 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.