
[ZDI-26-300|CVE-2026-41276] Flowise AccountService resetPassword Authentication Bypass Vulnerability (CVSS 8.1; Credit: Nicholas Zubrisky (@NZubrisky) of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-300/
Post summary
CVE-2026-41276, an authentication bypass in Flowise's AccountService resetPassword, has been disclosed with a CVSS of 8.1, but no exploit, PoC, or patch details are provided.

