AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73488

MEDIUM · CVSS 6 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Versions of Flowise prior to 3.1.3 are vulnerable to an insecure direct object reference in the API endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. This vulnerability can lead to unauthorized exposure of sensitive information, such as email addresses and account balances. Organizations using affected versions should prioritize patching to mitigate the risk of data breaches and protect customer privacy.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73488
Severity
MEDIUM
CVSS
6
EPSS
0.27%

Original NVD Description

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable customer IDs to retrieve sensitive information including email addresses, account balances, currency types, and billing configurations without authorization checks.