
CVE-2026-5022 The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download ima… https://www.cve.org/CVERecord?id=CVE-2026-5022
Post summary
The CVE report discloses an unauthenticated download vulnerability in a specific API endpoint, allowing unrestricted access to image files.
