CVE-2026-70476 | FlowiseAI Flowise up to 3.1.2 Billing organization.controller.ts subscriptionId improper authorization

SecurityVulns

A vulnerability was found in FlowiseAI Flowise up to 3.1.2 and classified as problematic. This issue affects some unknown processing of the file packages/server/src/enterprise/routes/organization.route.ts/packages/server/src/enterprise/controllers/organization.controller.ts of the component Billing. Such manipulation of the argument subscriptionId leads to improper authorization.

This vulnerability is listed as CVE-2026-70476. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More