THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gmmw-qg98-6j6p (high) — Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

[GHSA] GHSA-gmmw-qg98-6j6p (high) — Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

medgithub_advisoriesPublished 2026-08-04

GHSA-gmmw-qg98-6j6p Severity: high CVE: CVE-2026-70476

Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation

### Summary Several organization billing endpoints accept attacker-controlled Stripe identifiers (subscriptionId) without verifying that the identifier belongs to the authenticated user's organization. This allows an authenticated attacke

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gmmw-qg98-6j6p