Unrated severityNVD Advisory· Published Oct 1, 2026
CVE-2026-51894
CVE-2026-51894
Description
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.24.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.