What is CVE-2026-70474?
A vulnerability in Flowise where OAuth2 credential endpoints (authorize, callback, refresh) query credentials by id without a workspaceId filter, potentially allowing unauthorized access. Affects versions prior to 3.1.3; update to the latest version to remediate.
Azərbaycanca: Flowise platformunda OAuth2 etimadnamələri id ilə sorğulanarkən workspaceId filtrinin olmaması zəifliyi aşkarlanıb. Bu, autentifikasiya, callback və refresh endpoint-ləri vasitəsilə icazəsiz girişə səbəb ola bilər. 3.1.3 versiyasına qədər təsirli olan bu problemi aradan qaldırmaq üçün son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What security issue was discovered in Flowise regarding OAuth2 credentials?
OAuth2 credential endpoints query credentials by id without a workspaceId filter, potentially allowing unauthorized access through authorize, callback, and refresh endpoints.
How can one remediate CVE-2026-70474?
Update the Flowise platform to version 3.1.3 or later to remediate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.