What is CVE-2026-69252?
A broken access control vulnerability was found in Flowise's /api/v1/files endpoint, allowing low-privileged authenticated API keys to read or delete files without proper permission checks. Users are advised to upgrade to version 3.1.3 and review API key permissions.
Azərbaycanca: Flowise LLM interfeysində /api/v1/files yolunda səlahiyyət yoxlaması zəifliyi aşkarlanıb. Bu, aşağı səviyyəli API açarı olan şəxsə faylları icazəsiz oxumağa və ya silməyə imkan verir. İstifadəçilərə 3.1.3 versiyasına yeniləmə və API açar səlahiyyətlərini nəzərdən keçirmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which Flowise component is affected by CVE-2026-69252?
The vulnerability exists in the /api/v1/files endpoint, where broken access control allows low-privileged authenticated API keys to read or delete files without proper permission checks.
What measures should be taken to mitigate CVE-2026-69252?
Users are advised to upgrade Flowise to version 3.1.3 and review their API key permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.