What is CVE-2026-70475?
A vulnerability in Flowise UI for LLM flow building (CVE-2026-70475) affects versions prior to 3.1.3 due to missing checkAnyPermission() middleware on the PUT /api/v1/executions/:id endpoint. This allows any authenticated user to potentially perform unauthorized actions. Update to the latest version to mitigate the issue.
Azərbaycanca: Flowise LLM axın qurma interfeysində CVE-2026-70475 zəifliyi tapılıb. Bu, 3.1.3 versiyasından əvvəlki versiyalarda authenticated istifadəçi tərəfindən PUT /api/v1/executions/:id endpoint-ə checkAnyPermission() middleware-nin olmaması səbəbilə icazəsiz əməliyyat imkanı yaradır. Flowise-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Flowise are affected by CVE-2026-70475?
This vulnerability affects all versions of Flowise prior to version 3.1.3.
What is the root cause of CVE-2026-70475?
The root cause is the missing checkAnyPermission() middleware on the PUT /api/v1/executions/:id endpoint, which allows any authenticated user to perform unauthorized actions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.