CVE-2026-70476
published 2026-08-04CVE-2026-70476: Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in…
PriorityP349high8.3CVSS 4.0
AVNACLATPPRNUINVCNVIHVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.29%
20.8th percentile
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| flowiseai | flowise | < 3.1.2 | 3.1.2 |
| flowiseai | flowise | >= 0 < 3.1.3 | 3.1.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FlowiseAI Flowise up to 3.1.2 Billing organization.controller.ts subscriptionId improper authorization
vuldb·2026-08-04·CVSS 8.3
CVE-2026-70476 [HIGH] FlowiseAI Flowise up to 3.1.2 Billing organization.controller.ts subscriptionId improper authorization
A vulnerability was found in FlowiseAI Flowise up to 3.1.2 and classified as problematic. This issue affects some unknown processing of the file packages/server/src/enterprise/routes/organization.route.ts/packages/server/src/enterprise/controllers/organization.controller.ts of the component Billing. Such manipulation of the argument subscriptionId leads to improper authorization.
This vulnerability is listed as CVE-2026-70476. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
ghsa·2026-08-04
CVE-2026-70476 [HIGH] CWE-284 Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
### Summary
Several organization billing endpoints accept attacker-controlled Stripe identifiers (subscriptionId) without verifying that the identifier belongs to the authenticated user's organization. This allows an authenticated attacker to perform unauthorized Stripe subscription operations on other tenants. As a result, an authenticated user can manipulate the Stripe subscription of another organization by supplying a victim organization's subscriptionId.
This allows attackers to perform unauthorized billing operations such as changing subscription plans or modifying seat quantities, resulting in potential financial impact and service disruption.
### Details
Multiple organizatio
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FlowiseAI/Flowise/commit/4d7899d02ca370a5510406be5c91483085a412f9https://github.com/FlowiseAI/Flowise/pull/6321https://github.com/FlowiseAI/Flowise/releases/tag/[email protected]https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6phttps://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p
2026-08-04
Published