Medium severity4.3NVD Advisory· Published May 6, 2026· Updated May 7, 2026
CVE-2026-8027
CVE-2026-8027
Description
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argument userId/organizationId/workspaceId/email causes authorization bypass. The attack may be initiated remotely. The affected component should be upgraded.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- gist.github.com/YLChen-007/3584e6ffa0bba6367328ecf0b46b0e4bnvdExploitThird Party Advisory
- vuldb.com/submit/777657nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/361274nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/361274/ctinvdPermissions RequiredVDB Entry
News mentions
1- We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually IsThe Hacker News · May 5, 2026