CVE-2026-56276
Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidation by supplying a crafted password hash, establishing persistent account access after temporary session compromise.
| CWE | CWE-915 |
| Vendor | flowise |
| Product | flowise |
| Published | Jun 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for flowise flowise
Be the first to know when new unknown vulnerabilities affecting flowise flowise are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Flowise / Flowise
0 < 3.1.2
References
Credits
๐ berkdedekarginoglu