CVE-2026-67622: Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belo
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-67622
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-67622 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Flowise
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-70636: Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthentica…nvd · 2026-08-06
- highCVE-2026-67621: Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated…nvd · 2026-08-06
- high[NEW] [high] Flowise: Multiple vulnerabilitiescert-bund · 2026-08-05
- unknownCVE-2026-70478: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
- unknownCVE-2026-70477: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
- unknownCVE-2026-70476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…nvd · 2026-08-04
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06