CVE-2026-51893: Infiniflow ragflow vulnerability
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via tracemindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for investigation?
Deployments running infiniflow ragflow 0.24.0 should be prioritized because the affected trace_mindmap path is externally reachable and performs data access without a visible ownership, tenant, workspace, or membership check.
What does an attacker need to attempt exploitation?
An attacker needs to be able to reach the trace_mindmap path and supply an object or tenant identifier of their choosing. The provided information does not indicate that prior ownership or membership in the target object is required.
What is the likely security impact of this issue?
The missing binding between the caller and the requested object or tenant can allow access-control boundaries to be bypassed. This may expose data associated with another object, tenant, workspace, or membership scope.