Authorization bypass through user-controlled key in Flowise - CVE-2026-70476
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to manipulate another organization's Stripe subscription.
The vulnerability exists due to authorization bypass through a user-controlled key in the organization billing endpoints when processing attacker-supplied subscription identifiers. A remote attacker can send crafted requests with a victim organization's subscriptionId to manipulate another organization's Stripe subscription.
This affects cross-tenant billing operations including subscription plan changes and seat quantity updates.