← Vulnerability feed

Vulnerability record · CVE-2024-5276 · published 25 June 2024

CVE-2024-5276: Fortra FileCatalyst Workflow SQL injection allows data modification

Fortra · Filecatalyst Workflow

Fortra FileCatalyst Workflow contains a SQL injection flaw (CWE-89, improper input validation) that lets an attacker modify application data, including creating administrative users and deleting or altering database records. Data exfiltration via the injection is not possible. The issue affects all versions from 5.1.6 Build 135 and earlier.

9.1 CVSS 3.1 Critical EPSS 90% · top 0.2% CWE-20 · Improper input validationCWE-89 · SQL injection
9.1CVSS 3.1 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.1 with network reachability, no privileges or user interaction required, high EPSS, and a public exploit reference, though KEV listing is absent.

What it is

Fortra FileCatalyst Workflow contains a SQL injection flaw (CWE-89, improper input validation) that lets an attacker modify application data, including creating administrative users and deleting or altering database records. Data exfiltration via the injection is not possible. The issue affects all versions from 5.1.6 Build 135 and earlier.

Impact

An attacker can create administrative accounts and delete or modify data in the application database, leading to full application compromise and integrity loss. Confidentiality is not impacted per the CVSS vector.

Attack surface

Reachable over the network with no authentication and no user interaction when anonymous access is enabled on the Workflow system; otherwise an authenticated user is required. The CVSS vector is AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high (0.90067, 99.788th percentile) and a third-party advisory is tagged Exploit, indicating public exploit information exists.

What to do

  • Apply the vendor fix or mitigation from Fortra advisory FI-2024-008 and the FileCatalyst Workflow KB article; upgrade beyond 5.1.6 Build 135.
  • Disable anonymous access on FileCatalyst Workflow systems where it is not strictly required.
  • Restrict network exposure of the Workflow interface to trusted networks or place it behind a VPN or reverse proxy with access controls.
  • Enforce least privilege on the database account used by FileCatalyst Workflow to limit the scope of data modification.
  • Audit existing administrative accounts and database records for unauthorized changes.

Detection

  • Monitor Workflow and database logs for SQL syntax anomalies, unexpected query errors, or injection-like payloads in request parameters.
  • Alert on creation of new administrative users or privilege changes in FileCatalyst Workflow.
  • Baseline and monitor for unusual bulk deletions or modifications in the application database.
  • Review access logs for unauthenticated requests to Workflow endpoints when anonymous access is enabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-6633Fortra filecatalyst workflow information exposure vulnerabilityThe default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the…EPSS 1.2%9.8CVE-2024-25153Fortra filecatalyst workflow exposure of resource to wrong sphere vulnerabilityA directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp…EPSS 42%7.2CVE-2024-6632Fortra filecatalyst workflow sql injection vulnerabilityA vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which ca…EPSS 0.61%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2024-5276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.