CVE-2026-67621: Flowise 3.1.4 Missing Authorization on Document Store Mutation Endpoints
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67621?
CVE-2026-67621 has a high severity rating of 7.6.
What issue does CVE-2026-67621 describe?
CVE-2026-67621 describes a missing authorization vulnerability in Flowise that allows unauthorized document store operations.
How can I exploit CVE-2026-67621?
Attackers with view-level permissions can exploit CVE-2026-67621 by sending direct HTTP requests to unprotected mutation endpoints.
How do I fix CVE-2026-67621?
To remediate CVE-2026-67621, implement proper authorization checks on all document store mutation endpoints.
Which versions of Flowise are affected by CVE-2026-67621?
Flowise versions up to and including 3.1.4 are affected by CVE-2026-67621.