A critical insecure direct object reference flaw, tracked as CVE-2026-67622, affects Flowise through version 3.1.4 and allows authenticated users to access resources tied to other workspaces in multi-tenant deployments. The bug resides in the OpenAI Assistants integration, where assistants-related endpoints accept an arbitrary credential UUID and resolve it without verifying that the credential belongs to the caller’s active workspace. The vulnerability is classified as CWE-639 and has been rated CVSS 9.9 under v3.1, with reporting also citing a CVSS 4.0 score of 8.5.
By supplying another workspace’s credential UUID, an attacker can cause Flowise to use a victim workspace’s OpenAI Assistants credential, enabling cross-workspace access to assistant metadata, file listings, and vector stores, and allowing file uploads into victim workspaces. The flaw also creates a path to unauthorized OpenAI API consumption and potential billing impact on affected accounts. Public reporting said no active exploitation had been observed at publication, and a vendor fix was expected in a future Flowise release.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record states that the new CVE was received by disclosure@vulncheck.com on August 6, 2026.
On August 6, 2026, CVE-2026-67622 was published for Flowise through version 3.1.4, describing cross-workspace credential access, assistant metadata exposure, file and vector store listing access, and file upload impact in the OpenAI Assistants integration.
VulnCheck reported a missing authorization vulnerability in Flowise 2.2.4 through 3.1.4 affecting the POST /api/v1/openai-assistants-file/download endpoint. Because the endpoint was placed on the global authentication whitelist, unauthenticated attackers can bypass session and API key checks and retrieve private files from any chatflow if they know valid identifiers.
Security researchers CayCon and piropatriot discovered CVE-2026-67622, an IDOR flaw in Flowise's OpenAI Assistants integration that lets authenticated users supply another workspace's credential UUID without workspace ownership checks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcethreataft.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.