
CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploi… https://www.cve.org/CVERecord?id=CVE-2026-70636
Post summary
The text announces a new authentication bypass vulnerability in Flowise 3.1.4 that permits unauthenticated attackers access to the OAuth2 credential refresh endpoint, but no patch, PoC, or exploitation details are provided.


