Insufficiently protected credentials in Flowise - CVE-2026-46440
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain access to the application.
The vulnerability exists due to insufficiently protected credentials in the checkBasicAuth endpoint when handling authentication requests. A remote attacker can send repeated username and password guesses to gain access to the application.
User interaction is required for exploitation.