Improper access control in Flowise - #VU129615
Published: May 4, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper access control in the /api/v1/account/register endpoint when handling registration requests. A remote attacker can send a specially crafted request to bypass authentication.
This affects on-premise deployments and can be exploited after the organization setup has been completed.