CVE-2026-8028

A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit is now public and may be used. Upgrading the affected component is recommended.
References
Link Resource
https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b Exploit Third Party Advisory
https://vuldb.com/submit/777659 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361276 Third Party Advisory VDB Entry
https://vuldb.com/vuln/361276/cti Permissions Required VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*

History

07 May 2026, 14:47

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b - () https://gist.github.com/YLChen-007/1d52497b0221835f99367be61612746b - Exploit, Third Party Advisory
References () https://vuldb.com/submit/777659 - () https://vuldb.com/submit/777659 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361276 - () https://vuldb.com/vuln/361276 - Third Party Advisory, VDB Entry
References () https://vuldb.com/vuln/361276/cti - () https://vuldb.com/vuln/361276/cti - Permissions Required, VDB Entry
CPE cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
First Time Flowiseai flowise
Flowiseai

06 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 15:16

Updated : 2026-05-07 14:47


NVD link : CVE-2026-8028

Mitre link : CVE-2026-8028

CVE.ORG link : CVE-2026-8028


JSON object : View

Products Affected

flowiseai

  • flowise
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo