PT-2026-51490 · Flowise · Flowise
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flowise versions 3.0.7 and earlier
Description
An authenticated user can change the account email address, which serves as the login identifier and password-recovery channel, via the account profile endpoint. This process occurs without requiring confirmation from the original email address or the re-entry of the current password. By modifying the recovery email, an attacker can take over an account and abuse password reset mechanisms.
Recommendations
Update to version 3.0.10.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowise