THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-67621 (HIGH 7.6) — Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP reque

[NVD] CVE-2026-67621 (HIGH 7.6) — Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP reque

lownvdPublished 2026-08-06

CVE-2026-67621 CVSS: 7.6 HIGH Published: 2026-08-06T22:18:22.717

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67621