PT-2026-51775 · Flowise · Flowise

·

CVE-2026-56270

·

Published

2026-04-16

·

Updated

2026-06-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.0
Description A missing authentication issue exists in the '/api/v1/loginmethod' endpoint. Unauthenticated users can retrieve an organization's complete Single Sign-On (SSO) configuration, including OAuth client secrets in cleartext, by providing the organizationId parameter. This allows remote attackers to harvest sensitive API credentials for integrations with Google, Microsoft/Azure, GitHub, and Auth0. This issue affects both FlowiseAI Cloud and self-hosted instances where the endpoint is exposed.
Recommendations Update to version 3.1.0 or later. As a temporary workaround, restrict access to the '/api/v1/loginmethod' endpoint to minimize the risk of exploitation.

Exploit

Fix

DoS

Cleartext Storage of Sensitive Information

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56270
GHSA-6PCV-J4JX-M4VX

Affected Products

Flowise