Critical severity9.8NVD Advisory· Published Jul 12, 2026· Updated Jul 14, 2026
CVE-2026-56271
CVE-2026-56271
Description
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/FlowiseAI/Flowise/security/advisories/GHSA-cc4f-hjpj-g9p8nvdVendor Advisory
- www.vulncheck.com/advisories/flowise-weak-default-jwt-secrets-in-authentication-middlewarenvdThird Party Advisory
News mentions
0No linked articles in our index yet.