Insecure Direct Object Reference in Flowise Payment Processing for Multi-Customer Data Access
CVE-2026-73488
6MEDIUM
What is CVE-2026-73488?
Flowise versions prior to 3.1.3 are exposed to an insecure direct object reference vulnerability within the GET /api/v1/organization/customer-default-source endpoint. This flaw enables authenticated attackers to gain unauthorized access to sensitive information such as payment and profile data of other customers by altering the customerId parameter. The attackers can exploit predictable customer IDs to extract confidential details including email addresses, account balances, currency types, and billing configurations. This significant security oversight raises concerns regarding data privacy and protection for users relying on the platform.
Affected Version(s)
Flowise 0 < 3.1.3
Flowise 3.1.3
