Vulnerability Description
Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest sensitive user data including user IDs, names, account status, and timestamps by sending requests with known email addresses.
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jc5m-wrp2-qq38
- https://www.vulncheck.com/advisories/flowise-pii-disclosure-via-unauthenticated-
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-jc5m-wrp2-qq38
FAQ
What is CVE-2026-56267?
CVE-2026-56267 is a documented vulnerability. Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An ...
How severe is CVE-2026-56267?
CVSS scoring is not yet available for CVE-2026-56267. Check NVD for updates.
Is there a patch for CVE-2026-56267?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.