Remote Code Execution in Digiwin EasyFlow .NET via Insecure Deserialization
Digiwin EasyFlow .NET is vulnerable to an insecure deserialization flaw, enabling unauthenticated remote attackers to achieve arbitrary code execution via crafted serialized input.
CVE search metadata
CVE search record: CVE-2026-102455. Severity: critical. CVSS: 9.8. KEV: no. Product: EasyFlow .NET. Brief: Remote Code Execution in Digiwin EasyFlow .NET via Insecure Deserialization. Brief link: https://feed.craftedsignal.io/briefs/2026-09-easyflow-deserialization/
What's new
- 1. added coverage for EasyFlow .NET Sep 30, 10:34 via nvd
Digiwin EasyFlow .NET contains a critical security vulnerability (CVE-2026-102455) arising from improper deserialization of untrusted data. An unauthenticated, remote attacker can exploit this flaw by sending a specially crafted serialized payload to the affected application. Successful exploitation results in remote code execution (RCE) with the privileges of the web service account. Given the nature of deserialization vulnerabilities in .NET applications, this typically occurs when the application uses insecure formatter settings or fails to validate object types during the deserialization process. This threat is particularly significant for enterprise environments using EasyFlow .NET for workflow management, as it provides a direct path for attackers to gain full control over the application server without prior authentication.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary code on the underlying host server. This can lead to full system compromise, exfiltration of sensitive organizational data, lateral movement within the network, or the deployment of additional malicious payloads such as ransomware. The high CVSS score of 9.8 reflects the ease of access and the severity of the potential impact on affected enterprise deployments.
Recommendation
- Immediately isolate internet-facing EasyFlow .NET servers until patches are applied.
- Monitor web server logs for HTTP requests containing large or obfuscated base64-encoded blobs, which are often indicative of serialized .NET object delivery.
- Audit web server service accounts to ensure they operate with the principle of least privilege, limiting the potential impact of successful RCE.
- Engage with the Digiwin vendor support channel to obtain and apply the specific security update addressing CVE-2026-102455.
Immediate actions
Patch CVE-2026-102455 on all Digiwin EasyFlow .NET instances
Mitigations
Restrict external network access to EasyFlow .NET web interfaces
CVE-2026-102455