Insufficiently protected credentials in Flowise - CVE-2026-46440
Published: May 18, 2026
Flowise
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to the application.
The vulnerability exists due to insufficiently protected credentials in the checkBasicAuth endpoint when handling authentication requests. A remote attacker can send repeated username and password guesses to gain access to the application.
User interaction is required for exploitation.