What is CVE-2026-71962?
Flowise versions 2.2.4 through 3.1.4 have a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint. This flaw allows unauthenticated attackers to access private files because the endpoint is included in the global authentication whitelist, bypassing access controls. Users should upgrade to the latest version or remove the endpoint from the whitelist immediately.
Azərbaycanca: Flowise proqramının 2.2.4 - 3.1.4 versiyalarında POST /api/v1/openai-assistants-file/download endpoint-də autentifikasiya çatışmazlığı aşkarlanıb. Bu boşluq autentifikasiya olunmamış istifadəçilərə qlobal `whitelist`-ə əlavə edilmiş endpoint vasitəsilə fərdi fayllara icazəsiz giriş imkanı verir. İstifadəçilərə dərhal ən son versiyaya yeniləmə və ya təsirlənmiş endpoint-i `whitelist`-dən çıxarmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of Flowise are affected by CVE-2026-71962?
This missing authorization vulnerability affects Flowise versions 2.2.4 through 3.1.4.
What can an unauthenticated attacker achieve by exploiting CVE-2026-71962?
An attacker can gain unauthorized access to private files because the POST /api/v1/openai-assistants-file/download endpoint is included in the global authentication whitelist.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.