CVE-2026-8027: FlowiseAI Flowise User Controller authorization
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FlowiseAI Flowiseto a version that resolves this vulnerability.Fixed in 3.0.12 - Compensating control
Because the authorization bypass can be initiated remotely, restrict external/remote access to the FlowiseAI service endpoints (e.g., via firewall/ACL/ingress controls) to only trusted networks or users until the affected Flowise version is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8027?
CVE-2026-8027 is classified as a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2026-8027?
To address CVE-2026-8027, upgrade the FlowiseAI Flowise software to version 3.0.13 or later.
What components are affected by CVE-2026-8027?
CVE-2026-8027 affects the User Controller Handler component of FlowiseAI Flowise up to version 3.0.12.
Can CVE-2026-8027 lead to data breaches?
Yes, CVE-2026-8027 can lead to unauthorized access which may result in data breaches.
Is there a workaround for CVE-2026-8027?
Currently, the recommended solution for CVE-2026-8027 is to update to the latest software version as there are no effective workarounds.