CVE-2026-30823Disclosure(flowiseai / flowise)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch flowiseai flowise systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-07: 4Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 403-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30823 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account t… https://www.cve.org/CVERecord?id=CVE-2026-30823

    Post summary

    A brief disclosure of an IDOR vulnerability in Flowise prior to version 3.0.13, potentially allowing account takeover, with no additional PoC, patch, or exploitation details provided.

    00000171
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30823 - High Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise fe... https://www.thehackerwire.com/vulnerability/CVE-2026-30823/ https://t.co/QSGMcdFfIH

    Post summary

    A new CVE-2026-30823 is disclosed as an IDOR flaw in Flowise (before v3.0.13) that can lead to account takeover; no exploit code, PoC, or patch is provided.

    0000054
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30823 Insecure Direct Object Reference (IDOR) in Flowise Prior to 3.0.13 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30823

    Post summary

    The post announces CVE-2026-30823, noting it is an Insecure Direct Object Reference flaw affecting Flowise versions before 3.0.13, with more details linked.

    0000053
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30823: HIGH] Flowise patched a critical IDOR vulnerability in version 3.0.13, preventing account takeover and enterprise feature bypass through SSO configurations. #cybersecurity#cve,CVE-2026-30823,#cybersecurity https://cvefind.com/CVE-2026-30823

    Post summary

    Flowise has patched CVE‑2026‑30823, mitigating an IDOR flaw that could allow account takeover and feature bypass via SSO – no exploitation or PoC details are disclosed.

    0000062
    599 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more