Improper access control in Flowise - CVE-2026-69259

 

Improper access control in Flowise - CVE-2026-69259

Published: July 30, 2026


Vulnerability identifier: #VU140057
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69259
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the SQLite Record Manager node when processing user-supplied additional configuration. A remote user can override the database path to write a crafted SQLite database to an arbitrary file and trigger command execution to execute arbitrary code.

Exploitation requires an authenticated user and affects instances using the published Docker image where the process runs as root. A separate Puppeteer launch is used to read the malicious file from /etc/chromium/*.conf.


Affected software

Flowise

How to mitigate CVE-2026-69259

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins