ProjectDiscovery added Nuclei detection coverage for two high-severity access control issues affecting Langflow and Budibase. One template targets CVE-2026-21445, a broken access control flaw in Langflow that can expose sensitive conversation and transaction data to unauthenticated users and allow destructive actions such as message deletion through exposed API endpoints. The detection logic uses the /api/v1/monitor/messages endpoint, and automated review notes the vulnerability affects versions before the fixed production release Langflow 1.7.1, despite inconsistent versioning in the initial template text. The issue is rated CVSS 9.1.
A second template was introduced for CVE-2026-31816, an authentication bypass in Budibase caused by improper regex validation in authorization middleware. The template attempts to detect the flaw by sending a crafted POST request to a user search endpoint using a webhook query-parameter pattern that could bypass authorization checks and enable user enumeration. ProjectDiscovery's automated review flagged implementation problems in the draft template, including an undefined variable, incorrect CWE mapping, missing vendor metadata, and weak matchers that could lead to false positives, but the underlying vulnerability was still classified as critical with a CVSS 9.1 score.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A pull request was opened in ProjectDiscovery's nuclei-templates repository to add detection for the Budibase authentication bypass. Automated review identified issues including an undefined variable, incorrect CWE mapping, missing vendor metadata, and weak matchers that could lead to false positives.
A pull request was published in the nuclei-templates repository adding detection coverage for the Langflow vulnerability using the /api/v1/monitor/messages endpoint. The accompanying review said the template had been validated against both vulnerable and patched targets and flagged a remediation-version inconsistency.
CVE-2026-31816 was identified in Budibase as an authentication or authorization bypass caused by improper regex validation in authorization middleware. The issue could allow unauthorized user enumeration via a crafted request to a user search endpoint, and the template metadata rates it CVSS 9.1.
A critical broken access control vulnerability, CVE-2026-21445, was disclosed in Langflow, allowing unauthenticated access to sensitive conversation and transaction data and enabling destructive actions such as message deletion through exposed API endpoints. Review notes indicate the fixed production release is Langflow 1.7.1, despite inconsistent remediation version text in the template.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.