Missing Authorization in Flowise - CVE-2026-70474

 

Missing Authorization in Flowise - CVE-2026-70474

Published: July 30, 2026


Vulnerability identifier: #VU140069
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-70474
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose OAuth2 credential metadata across workspaces.

The vulnerability exists due to improper access control in the OAuth2 authorize endpoint when handling credential authorization requests by credential ID without workspace scoping. A remote user can send an authorization request for another workspace's credential to disclose OAuth2 credential metadata across workspaces.

The returned authorization data can expose values such as the client identifier, requested scope, and redirect URI.


Affected software

Flowise

How to mitigate CVE-2026-70474

Install security update from vendor's website.

Flowise - update to 3.1.3

External References

Related Security Bulletins