Access Control Vulnerability in Flowise Product
CVE-2026-69262
7.1HIGH
What is CVE-2026-69262?
An access control vulnerability exists in Flowise, allowing unauthorized deletion of resources. When calling the DELETE API for chatflows, the application incorrectly validated permissions. Users with permission to delete agentflows could remove chatflows and vice versa. This issue is addressed in version 3.1.3, ensuring proper checks are in place to prevent unauthorized access to delete operations.
Affected Version(s)
Flowise < 3.1.3
