Tangro's vulnerability profile centers on a specialized business-workflow platform where the recurring exposure involves authentication and authorization weaknesses—including user-controlled key bypass, capture-replay attacks, authentication bypass for critical functions, and insecure storage of sensitive information—alongside improper resource transfer between security boundaries. These patterns reflect the access-control and data-handling demands of workflow platforms that mediate privilege and data flow across organizational roles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tangro over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26174HIGH tangro Business Workflow before 1.18.1 requests a list of allowed filetypes from the server and restricts uploads to the filetypes contained in this list. However, this restriction | Dec 18, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-26172MEDIUM Every login in tangro Business Workflow before 1.18.1 generates the same JWT token, which allows an attacker to reuse the token when a session is active. The JWT token does not con | Dec 18, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-26175MEDIUM In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users. | Dec 18, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-26178MEDIUM In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated. | Dec 18, 2020 | 5.3 | 18 | NO | NO |
CVE-2020-26177MEDIUM In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restricti | Dec 18, 2020 | 4.3 | 17 | NO | NO |
CVE-2020-26176MEDIUM An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a | Dec 18, 2020 | 4.3 | 17 | NO | NO |
CVE-2020-26173MEDIUM An incorrect access control implementation in Tangro Business Workflow before 1.18.1 allows an attacker to download documents (PDF) by providing a valid document ID and token. No f | Dec 18, 2020 | 4.3 | 17 | NO | NO |
CVE-2020-26171MEDIUM In tangro Business Workflow before 1.18.1, the documentId of attachment uploads to /api/document/attachments/upload can be manipulated. By doing this, users can add attachments to | Dec 18, 2020 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tangro.
Media articles that mention a CVE ID that affects a product developed by Tangro — matched by CVE ID, not by vendor name.