References https://github.com/LandGrey/flink-unauth-rce https://www.exploit-db.com/exploits/48978 https://beaglesecurity.com/blog/vulnerability/apache-flink-unauth-rce.html https://s4e.io/tools/apache-flink-unauth-rce-vulnerability-scanner https://adamc95.medium.com/apache-flink-1-9-x-part-1-set-up-5d85fd2770f3 https://github.com/AleWong/Apache-Flink-Web-Dashboard-RCE https://blog.csdn.net/lx_lyt/article/details/103133361 https://github.com/murataydemir/CVE-2020-17519 https://cloud.tencent.com/developer/article/1544254 https://zhuanlan.zhihu.com/p/328382373 https://developer.aliyun.com/ask/639656 https://www.c0bra.xyz/2019/11/14/Apache-Flink-RCE-%E5%A4%8D%E7%8E%B0/ https://juejin.cn/post/6976258895316680741 https://www.cnblogs.com/Sylon/p/11868380.html https://www.rapid7.com/db/modules/exploit/multi/http/apache_flink_jar_upload_exec/ https://nsfocusglobal.com/advisory-apache-flink-remote-code-execution-vulnerability/
Related VulnerabilitiesPoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposurePoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2025-51683: mJobTime <= 15.7.2 - Unauthenticated Blind SQL Injection to RCEPoCCVE-2026-0561: Shield Security <= 21.0.8 - Unauthenticated Reflected XSSPoCCVE-2026-0768: Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_codePoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account TakeoverPoCCVE-2026-21875: ClipBucket v5 <= 5.5.2 - Unauthenticated Blind SQL InjectionPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File ReadPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal