CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-73488

unknowncovered by 1 sourcefirst seen 2026-08-13
Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.

⚡ Watch CVE-2026-73488

Get an email if CVE-2026-73488 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-73488

CVE.org record

Embed the live status

CVE-2026-73488 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-73488 status](https://www.csirts.com/badge/CVE-2026-73488)](https://www.csirts.com/cve/CVE-2026-73488)