CVE-2026-41276Disclosure(flowiseai / flowise)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific flaw exists within the resetPassword method of the AccountService class. There is no check performed to ensure that a password reset token has actually been generated for a user account. By default the value of the reset token stored in a users account is null, or an empty string if they've reset their password before. An attacker with knowledge of the user's email address can submit a request to the "/api/v1/account/reset-password" endpoint containing a null or empty string reset token value and reset that user's password to a value of their choosing. This vulnerability is fixed in 3.1.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-23: 1Mentions · 2026-04-30: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-30: 104-2304-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-300|CVE-2026-41276] Flowise AccountService resetPassword Authentication Bypass Vulnerability (CVSS 8.1; Credit: Nicholas Zubrisky (@NZubrisky) of TrendAI Research) https://www.zerodayinitiative.com/advisories/ZDI-26-300/

    Post summary

    CVE-2026-41276, an authentication bypass in Flowise's AccountService resetPassword, has been disclosed with a CVSS of 8.1, but no exploit, PoC, or patch details are provided.

    02020913
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41276 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authenti… https://www.cve.org/CVERecord?id=CVE-2026-41276

    Post summary

    The statement announces CVE‑2026‑41276 as a remote authentication bypass in Flowise prior to version 3.1.0, linking to the CVE record.

    0000056
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more