ID:13072 - Exploit for Improper access control in Flowise - CVE-2026-56274

 
Main Vulnerability Database Exploits ID:13072 - Exploit for Improper access control in Flowise - CVE-2026-56274

ID:13072 - Exploit for Improper access control in Flowise - CVE-2026-56274

Published: September 14, 2026


Vulnerability identifier: #VU131708
Vulnerability risk: Medium
CVE-ID: CVE-2026-56274
CWE-ID: CWE-284
Exploitation vector: Remote access
Vulnerable software:
Flowise

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the MCP command validation logic when processing custom MCP server command configurations. A remote user can supply a crafted command such as a docker build invocation to execute arbitrary code.

Exploitation requires a Flowise account or an API key with view and update permissions for chatflows, and the target environment must have the docker command available.


Remediation

Install security update from vendor's website.