CVE-2026-56267

MEDIUM

Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint

Title source: cna
STIX 2.1

Description

Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest sensitive user data including user IDs, names, account status, and timestamps by sending requests with known email addresses.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-jc5m-wrp2-qq38
https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jc5m-wrp2-qq38
Third Party Advisory third-party-advisory
VulnCheck Advisory: Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint
https://www.vulncheck.com/advisories/flowise-pii-disclosure-via-unauthenticated-forgot-password-endpoint

Scores

CVSS v4 6.9
EPSS 0.0033
EPSS Percentile 24.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
Flowise/Flowise < 3.0.13
Flowise/Flowise 3.0.13
Published Jun 20, 2026
Tracked Since Jun 20, 2026