CVE-2026-67622
CRITICALFlowise 3.1.4 IDOR in OpenAI Assistants Integration
Title source: cnaDescription
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67622.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/flowise-idor-in-openai-assistants-integration
Scores
CVSS v3
9.9
EPSS
0.0025
EPSS Percentile
16.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-639
Status
published
Products (1)
FlowiseAI/Flowise
< 3.1.4
Published
Aug 06, 2026
Tracked Since
Aug 07, 2026