📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h Global ransomware Multiple sectors CRITICAL 16h Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h Global ransomware Multiple sectors CRITICAL 16h Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 15h Global apt Critical Infrastructure CRITICAL 15h Global ransomware Multiple sectors CRITICAL 16h
Vulnerabilities

CVE-2026-41266

High ⚡ Exploit Available
CWE-200 — Weakness Type
Published: Apr 23, 2026  ·  Modified: Apr 30, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID can retrieve credentials stored in password type fields and HTTP headers, leading to credential theft and more. This vulnerability is fixed in 3.1.0.

🤖 AI Executive Summary

Flowise versions prior to 3.1.0 expose sensitive data including API keys, HTTP authorization headers, and internal configuration through an unauthenticated API endpoint. An attacker with only a chatflow UUID can retrieve stored credentials, leading to credential theft and potential lateral movement. This vulnerability poses significant risk to organizations deploying Flowise for AI/LLM applications, particularly those handling sensitive business logic or integrations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 06:55
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations in financial services (banking sector under SAMA oversight), government agencies (NCA jurisdiction), healthcare providers, and energy sector (ARAMCO and subsidiaries) face significant risk if deploying Flowise for customer-facing AI chatbots or internal LLM workflows. The exposure of API keys and authorization headers could compromise integrations with critical backend systems, payment gateways, and sensitive databases. Government entities and critical infrastructure operators are particularly vulnerable due to the potential for credential theft leading to unauthorized access to classified or sensitive systems.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Healthcare and Medical Services Energy and Utilities Telecommunications E-commerce and Retail Insurance Education
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Flowise instances in your environment and document their versions
2. Audit access logs for the /api/v1/public-chatbotConfig/:id endpoint to detect potential exploitation
3. Rotate all API keys, credentials, and HTTP authorization headers that may have been exposed
4. Implement network-level access controls to restrict access to Flowise instances

PATCHING:
1. Upgrade to Flowise 3.1.0 or later immediately when available
2. If upgrade is not immediately possible, disable or restrict access to the /api/v1/public-chatbotConfig/:id endpoint

COMPENSATING CONTROLS:
1. Implement Web Application Firewall (WAF) rules to block requests to /api/v1/public-chatbotConfig/:id endpoint
2. Deploy API gateway authentication layer requiring valid credentials for all API access
3. Implement IP whitelisting to restrict access to Flowise instances to known trusted networks
4. Enable comprehensive API logging and monitoring for all Flowise endpoints
5. Implement secrets management solution to store credentials outside of Flowise configuration

DETECTION:
1. Monitor for HTTP GET/POST requests to /api/v1/public-chatbotConfig/ with UUID parameters
2. Alert on successful responses containing 'apiKey', 'authorization', or 'password' fields from this endpoint
3. Track unusual access patterns to this endpoint from external IP addresses
4. Implement SIEM rules to detect credential extraction attempts
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع مثيلات Flowise في بيئتك وتوثيق إصداراتها
2. تدقيق سجلات الوصول لنقطة النهاية /api/v1/public-chatbotConfig/:id للكشف عن الاستغلال المحتمل
3. تدوير جميع مفاتيح API وبيانات الاعتماد ورؤوس التفويض HTTP التي قد تكون قد تعرضت
4. تنفيذ عناصر تحكم الوصول على مستوى الشبكة لتقييد الوصول إلى مثيلات Flowise

التصحيح:
1. الترقية إلى Flowise 3.1.0 أو إصدار أحدث فوراً عند توفره
2. إذا لم يكن الترقية ممكنة فوراً، قم بتعطيل أو تقييد الوصول إلى نقطة النهاية

عناصر التحكم البديلة:
1. تنفيذ قواعد جدار حماية تطبيقات الويب لحظر الطلبات إلى نقطة النهاية
2. نشر طبقة مصادقة بوابة API تتطلب بيانات اعتماد صحيحة
3. تنفيذ القائمة البيضاء للعناوين IP لتقييد الوصول إلى الشبكات الموثوقة
4. تفعيل السجلات الشاملة ومراقبة جميع نقاط نهاية Flowise
5. تنفيذ حل إدارة الأسرار لتخزين بيانات الاعتماد خارج التكوين

الكشف:
1. مراقبة طلبات HTTP إلى نقطة النهاية مع معاملات UUID
2. التنبيه على الاستجابات الناجحة التي تحتوي على حقول حساسة
3. تتبع أنماط الوصول غير العادية من عناوين IP خارجية
4. تنفيذ قواعد SIEM للكشف عن محاولات استخراج بيانات الاعتماد
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 - 5.1.1: Access Control and Authentication ECC 2024 - 5.2.1: Cryptographic Controls ECC 2024 - 6.1.1: Incident Detection and Response ECC 2024 - 7.1.1: Data Protection and Privacy
🔵 SAMA CSF
SAMA CSF - Governance: Information Security Governance SAMA CSF - Protect: Access Control and Authentication SAMA CSF - Protect: Data Protection SAMA CSF - Detect: Security Monitoring and Logging
🟡 ISO 27001:2022
ISO 27001:2022 - A.5.2: User Access Management ISO 27001:2022 - A.5.3: Access Rights ISO 27001:2022 - A.8.2: Cryptography ISO 27001:2022 - A.8.3: Cryptographic Key Management ISO 27001:2022 - A.12.4: Logging
🟣 PCI DSS v4.0.1
PCI DSS 4.1: Render PAN unreadable PCI DSS 6.2: Security patches and updates PCI DSS 7.1: Limit access to system components PCI DSS 10.2: Implement automated audit trails
📦 Affected Products / CPE 1 entries
flowiseai:flowise
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityN — None / Network
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-200
EPSS0.04%
Exploit ✓ Yes
Patch ✗ No
Published 2026-04-23
Source Feed nvd
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-200
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.