Missing Authorization in Flowise - CVE-2026-41266
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authorization in the /api/v1/public-chatbotConfig/:id endpoint when handling requests for public chatbot configuration data. A remote attacker can send a request with a known chatflow UUID to disclose sensitive information.
Knowledge of a chatflow UUID is the only prerequisite and may be obtained from embedded chat widgets, referrer headers, or logs.