THREAT OPS › Threat News › [NVD] CVE-2026-67621 (HIGH 7.6) — Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP reque
[NVD] CVE-2026-67621 (HIGH 7.6) — Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP reque
CVE-2026-67621 CVSS: 7.6 HIGH Published: 2026-08-06T22:18:22.717
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to
Indicators of compromise
- CVE-2026-67621cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67621