PT-2026-55225 · Drupal+3 · Flowdrop+1

·

CVE-2026-58590

·

Published

2026-07-01

·

Updated

2026-07-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FlowDrop versions 0.0.0 through 1.6.0
Description A missing authorization issue allows forceful browsing. The module, which enables testing and running AI-driven workflows via a chat interface, fails to sufficiently re-evaluate human-in-the-loop approval gates during workflow iterations that occur more than once. This can lead to the execution of workflows not intended by the user. Exploitation requires the attacker to possess the "Administer FlowDrop workflows" role or equivalent permissions such as "Create FlowDrop workflows" or "Edit FlowDrop workflows".
Recommendations Update FlowDrop to a version later than 1.6.0.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58590
DRUPAL-CONTRIB-2026-068

Affected Products

Flowdrop
Drupal/Flowdrop