Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
Flowise - Weak Default JWT Secrets in Authentication Middleware
CVE-2026-56271
Description
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-cc4f-hjpj-g9p8mitrevendor-advisory
- www.vulncheck.com/advisories/flowise-weak-default-jwt-secrets-in-authentication-middlewaremitrethird-party-advisory
News mentions
0No linked articles in our index yet.