#VU125536 Unverified Password Change in Flowise
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote user to gain control of the account.
The vulnerability exists due to unverified password change in the account security settings when changing an account password. A remote user can change the password without supplying the current password to gain control of the account.
The issue affects password changes performed without current-password verification or additional verification.