CVE-2026-70636Disclosure(flowiseai / flowise)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flowise

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
flowise

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-07: 2Mentions · 2026-08-08: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-08: 108-0708-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-072
Disclosure2
2026-08-081
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploi… https://www.cve.org/CVERecord?id=CVE-2026-70636

    Post summary

    The text announces a new authentication bypass vulnerability in Flowise 3.1.4 that permits unauthenticated attackers access to the OAuth2 credential refresh endpoint, but no patch, PoC, or exploitation details are provided.

    00011724
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🤖 Flowise authentication bypass discovered CVE-2026-70636 affects Flowise through 3.1.4. An authentication-middleware weakness can expose the OAuth2 credential-refresh endpoint to unauthenticated requests, potentially allowing unauthorized OAuth token rotation across workspaces. The issue is described as a bypass of an earlier Flowise vulnerability. 🔎 Source: Tenable / CVE. #Flowise #AISecurity #OAuth #CVE #CyberSecurity

    Post summary

    The post discloses CVE‑2026‑70636 in Flowise 3.1.4, detailing an authentication‑middleware flaw that exposes the OAuth2 token‑refresh endpoint to unauthenticated requests, potentially allowing unauthorized token rotation. No PoC, exploit, patch, or active exploitation information is provided.

    0000045
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploi… https://www.cve.org/CVERecord?id=CVE-2026-70636 ----- Traducción: CVE-2026-70636 Flo… http://infoflow.cloud`

    Post summary

    The post discloses an authentication bypass in Flowise 3.1.4 (CVE‑2026‑70636) that allows unauthenticated attackers to reach the OAuth2 credential refresh endpoint, linking only to the CVE record without providing PoC or exploitation details.

    0000060
    98 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflowiseaiflowise---

Explore more