CVE-2026-67621

HIGH

Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints

Title source: cna
STIX 2.1

Description

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
Sunset Announcement
https://flowiseai.com/sunset

Scores

CVSS v3 7.6
EPSS 0.0027
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
FlowiseAI/Flowise < 3.1.4
Published Aug 06, 2026
Tracked Since Aug 07, 2026