Vulnerability Description
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter. Remote attackers can send a GET request to harvest sensitive API credentials for Google, Microsoft/Azure, GitHub, and Auth0 integrations. This affects FlowiseAI Cloud and self-hosted instances where the endpoint is exposed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | < 3.1.0 |
Related Weaknesses (CWE)
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6pcv-j4jx-m4vxExploitVendor Advisory
- https://www.vulncheck.com/advisories/flowise-unauthenticated-oauth-secrets-disclThird Party Advisory
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6pcv-j4jx-m4vxExploitVendor Advisory
FAQ
What is CVE-2026-56270?
CVE-2026-56270 is a vulnerability with a CVSS score of 7.5 (HIGH). Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's c...
How severe is CVE-2026-56270?
CVE-2026-56270 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56270?
Check the references section above for vendor advisories and patch information. Affected products include: Flowiseai Flowise.