受影响的 Flowintel 版本将 API 端点对所有已认证的 API 用户开放。该端点接受一个 参数,用于指定要返回任务分配信息的用户,但此前除了基本的 API 认证外,没有任何基于角色的访问限制。 因此,权限较低的已认证用户可以通过提供目标用户的标识符,潜在地查询其他用户的任务分配信息。 修复内容如下: 将方法装饰器从: 更改为: 这样,只有管理员或组织管理员才能执行跨用户的任务分配查询。 受影响版本:大于 3.3.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81826 | 9.1 CRITICAL | Flowintel Fails to Invalidate Active Sessions After Password Change |
| CVE-2026-81662 | 8.6 HIGH | Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configur |
| CVE-2026-81818 | 8.6 HIGH | Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Pr |
| CVE-2026-81743 | 7.5 HIGH | Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template Injection |
| CVE-2026-81817 | 7.2 HIGH | Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification |
| CVE-2026-81659 | 7.1 HIGH | Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing |
| CVE-2026-81827 | 6.9 MEDIUM | Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Email Input |
| CVE-2026-81814 | 5.1 MEDIUM | Flowintel Stored XSS in Calendar via Malicious Case Title |
| CVE-2026-81753 | 5.1 MEDIUM | Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content |
| CVE-2026-81820 | 5.1 MEDIUM | Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes |
No comments yet