Access Control Flaw in Flowise by FlowiseAI
CVE-2026-69252

7.2HIGH

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-69252?

The Flowise platform exposes a significant access control vulnerability in its API. Prior to version 3.1.3, the /api/v1/files endpoint was inadequately protected, allowing low-privileged authenticated users to execute GET and DELETE requests without proper permission checks. This oversight enabled attackers to list files associated with an organization's storage root and remove files from other workspaces within the same organization using manipulated paths. The issue has been resolved in version 3.1.3, but users of earlier versions should upgrade immediately to secure their systems against unauthorized access.

Affected Version(s)

Flowise < 3.1.3

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.