CVE-2026-67621: Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unpr
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67621
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67621 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Flowise
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-70636: Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthentica…nvd · 2026-08-06
- criticalCVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI…nvd · 2026-08-06
- high[NEW] [high] Flowise: Multiple vulnerabilitiescert-bund · 2026-08-05
- unknownCVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
- unknownCVE-2026-70477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
- unknownCVE-2026-70476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06