CVE-2026-56267Disclosure

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-20: 3Technical Details · 2026-06-20: 306-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-56267 Information Exposure in Flowise Before 3.0.13 POST Account Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56267

    Post summary

    The notice briefly reports CVE‑2026‑56267 as an information‑exposure flaw in Flowise's POST account endpoint, but offers no proof of concept, exploit, patch, or evidence of active exploitation.

    0000042
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56267 Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII… https://www.cve.org/CVERecord?id=CVE-2026-56267 ----- Traducción: CVE-2026-56267 Flo… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑56267, describing an information‑exposure flaw in Flowise’s forgot‑password endpoint that leaks full user objects containing PII; it includes a link to the CVE record but offers no PoC, exploit, or patch details.

    0000029
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56267 Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII… https://www.cve.org/CVERecord?id=CVE-2026-56267

    Post summary

    The post announces CVE-2026-56267, detailing an information‐exposure flaw in Flowise’s forgot‑password endpoint that leaks user data, but does not provide PoC, exploit, or patch information.

    00000298
    57.7K followersView on X

Explore more