Unverified Password Change in Flowise - #VU125536
Published: April 9, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote user to gain control of the account.
The vulnerability exists due to unverified password change in the account security settings when changing an account password. A remote user can change the password without supplying the current password to gain control of the account.
The issue affects password changes performed without current-password verification or additional verification.