Plaintext Credential Validation in Flowise Affects User Security
CVE-2026-46440

7.5HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-46440?

Flowise, a drag-and-drop user interface for creating custom large language model flows, had a significant security issue prior to version 3.1.2. The checkBasicAuth endpoint used plaintext credential validation without implementing rate limiting and direct comparison methods, making it vulnerable to unauthorized access. This risk has been addressed and patched in version 3.1.2, enhancing the overall security of the platform.

Affected Version(s)

Flowise < 3.1.2

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.