High severity7.6NVD Advisory· Published Aug 6, 2026· Updated Sep 15, 2026
CVE-2026-67621
CVE-2026-67621
Description
Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.mdnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/flowise-missing-authorization-on-document-store-mutation-endpointsnvdThird Party Advisory
- flowiseai.com/sunsetnvdNot Applicable
News mentions
1- Flowise: Critical IDOR and High SSRF Among Four Disclosed VulnerabilitiesVypr Intelligence · Aug 8, 2026