CVE-2026-8028: FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. Upgrading the affected component is recommended.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8028?
CVE-2026-8028 has been rated as a moderate severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2026-8028?
To fix CVE-2026-8028, upgrade FlowiseAI Flowise to version 3.0.13 or later.
What components are affected by CVE-2026-8028?
CVE-2026-8028 affects the endpoint functionality related to account verification in FlowiseAI Flowise versions up to 3.0.12.
What impact does CVE-2026-8028 have on my system?
CVE-2026-8028 can lead to information disclosure through the manipulation of the verify function in the account service.
Is CVE-2026-8028 exploitable remotely?
Yes, CVE-2026-8028 can be exploited remotely if the affected service is accessible over a network.