CVE-2026-39915 is a high-severity vulnerability in TIM Flow before version 26.0.6, allowing remote attackers to inject arbitrary HTTP headers and response body content via the rt URL parameter. This CRLF injection vulnerability can lead to session token theft and account credential modification. Defenders should assess exposure and potential impact, as authenticated users may be vulnerable to session toke [truncated]
CVE-2026-39914 is an improper authorization vulnerability in TIM Flow before 26.0.6 that allows authenticated users to submit arbitrary SQL queries to a privileged dashboard Excel export endpoint. This could enable attackers to retrieve sensitive database contents as a downloadable spreadsheet, bypassing role-based access controls. The vulnerability has a high CVSS score of 7.1 and is considered a signifi [truncated]