CVE-2026-56272
Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing
CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.
| CWE | CWE-916 |
| Vendor | flowise |
| Product | flowise |
| Published | Jun 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for flowise flowise
Be the first to know when new medium vulnerabilities affecting flowise flowise are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Flowise / Flowise
0 < 3.0.13
References
Credits
๐ kolega-ai-dev