PT-2026-67821 · Flowise · Flowise

CVE-2026-70475

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Flowise versions prior to 3.1.3
Description An authorization flaw exists where the 'PUT /api/v1/executions/:id' endpoint lacks the checkAnyPermission() middleware used to protect other execution endpoints. This allows any authenticated user, regardless of their assigned permissions, to modify the execution state, data, and metadata of any execution within their workspace. This can lead to privilege escalation and the manipulation of workflow execution results.
Recommendations Update to version 3.1.3.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70475
GHSA-FM2F-4339-4P2F

Affected Products

Flowise