CVE-2026-56267: Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint
Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest sensitive user data including user IDs, names, account status, and timestamps by sending requests with known email addresses.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56267?
CVE-2026-56267 has a risk score of 50, indicating a moderate severity level.
How do I fix CVE-2026-56267?
To fix CVE-2026-56267, update Flowise to version 3.0.13 or later, which resolves the unauthenticated information exposure.
What kind of data is exposed in CVE-2026-56267?
CVE-2026-56267 exposes full user objects, including Personally Identifiable Information (PII), to unauthenticated attackers.
How can an attacker exploit CVE-2026-56267?
An attacker can exploit CVE-2026-56267 by sending requests to the POST /api/v1/account/forgot-password endpoint to enumerate valid email addresses.
What product is affected by CVE-2026-56267?
CVE-2026-56267 affects the Flowise software prior to version 3.0.13.