CVE-2026-67621
HIGHFlowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
Title source: cnaDescription
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/flowise-missing-authorization-on-document-store-mutation-endpoints
Scores
CVSS v3
7.6
EPSS
0.0027
EPSS Percentile
19.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
FlowiseAI/Flowise
< 3.1.4
Published
Aug 06, 2026
Tracked Since
Aug 07, 2026