MCPA-2026-0056
highauth-missingCVSS 7.5
Flowise unauthenticated OAuth2 credential refresh via prefix-based whitelist bypass (CVE-2026-70636)
Flowise through 3.1.4: the authentication middleware whitelist uses prefix matching, so a POST to the oauth2-credential refresh route with a trailing credential identifier bypasses all authentication and authorization, letting unauthenticated attackers trigger OAuth token rotation for credentials in any workspace (a bypass of the CVE-2026-41273 fix). No fixed release: Flowise announced its sunset; through 3.1.4 (latest) remains affected.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | flowise | >= 0, <= 3.1.4 |
Identifiers
CVE-2026-70636GHSA-rm9r-9424-cccfCWE-862
References
- advisory https://github.com/advisories/GHSA-rm9r-9424-cccf
- web https://nvd.nist.gov/vuln/detail/CVE-2026-70636
- web https://flowiseai.com/sunset
Timeline
- Published: 2026-08-07