Insecure Direct Object Reference in Flowise Payment Processing for Multi-Customer Data Access
CVE-2026-73488

6MEDIUM

Key Information:

Vendor

Flowiseai

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-73488?

Flowise versions prior to 3.1.3 are exposed to an insecure direct object reference vulnerability within the GET /api/v1/organization/customer-default-source endpoint. This flaw enables authenticated attackers to gain unauthorized access to sensitive information such as payment and profile data of other customers by altering the customerId parameter. The attackers can exploit predictable customer IDs to extract confidential details including email addresses, account balances, currency types, and billing configurations. This significant security oversight raises concerns regarding data privacy and protection for users relying on the platform.

Affected Version(s)

Flowise 0 < 3.1.3

Flowise 3.1.3

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

truongvip1
.