CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-5022
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
Original NVD Description
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.
Related CVEs
Other vulnerabilities affecting the same vendor(s)