A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.
Conclusion & alert: CVE-2024-5276 is rated High Exploit Risk (89.2/100): CVSS Critical severity, with high exploitation likelihood (EPSS 87.42%, 99th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-02 | 87.20% | 87.42% | +0.21% |
| 2 | 2026-04-21 | 87.09% | 87.20% | +0.12% |
| 3 | 2026-04-19 | — | 87.09% | — |
Full EPSS history (28 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | df4dee71-de3a-4139-9588-11b62fe6c0ff |
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| fortra | filecatalyst_workflow | < 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:*:*:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:-:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:build112:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:build114:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:build126:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:build130:*:*:*:*:*:* |
| fortra | filecatalyst_workflow | 5.1.6 | cpe:2.3:a:fortra:filecatalyst_workflow:5.1.6:build135:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0 | Mitigation Vendor Advisory |
| https://www.fortra.com/security/advisory/fi-2024-008 | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2024-25 | Exploit Third Party Advisory |