THREAT OPS › Threat News › [NVD] CVE-2026-70636 (HIGH 7.5) — Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constan
[NVD] CVE-2026-70636 (HIGH 7.5) — Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constan
CVE-2026-70636 CVSS: 7.5 HIGH Published: 2026-08-06T22:18:28.150
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-70636cve
- CVE-2026-41273cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70636