Improper access control in Flowise - CVE-2026-70478
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and access connected third-party services.
The vulnerability exists due to improper access control in the OAuth2 token refresh endpoint when handling unauthenticated refresh requests for a credential ID. A remote attacker can send a crafted POST request to obtain a refreshed access token and access connected third-party services.
Exploitation requires knowledge of a credential ID, which may be obtained through enumeration or other information leaks.