以下是该漏洞描述的中文翻译: 受影响的 Flowintel 版本在用户修改密码时,未撤销用户已有的认证会话。 这意味着,如果攻击者已经持有有效的会话(例如,来自之前的访问或被盗取的会话令牌),受害者更改密码并不会终止该攻击者的访问权限。该会话将保持可用,直到其自然过期。上游提交直接对此进行了说明:“会话将持续有效直至其到期。” 修复方案是检测密码变更,并在数据库更新后显式调用 。此修复同时应用于 和 两个函数。 受影响的版本:>= 3.3.0
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81662 | 8.6 HIGH | Flowintel Alert Settings Configuration Allows Remote Code Execution via Arbitrary Configur |
| CVE-2026-81818 | 8.6 HIGH | Flowintel Organization Administrator Can Reset Full Administrator Password and Escalate Pr |
| CVE-2026-81743 | 7.5 HIGH | Flowintel Arbitrary Log File Path Allows Remote Code Execution via Template Injection |
| CVE-2026-81817 | 7.2 HIGH | Flowintel Missing Task-to-Case Authorization Allows Cross-Case Task Modification |
| CVE-2026-81659 | 7.1 HIGH | Flowintel Note PDF Export Allows Arbitrary Local File Read via Pandoc/XeLaTeX Processing |
| CVE-2026-81827 | 6.9 MEDIUM | Flowintel Login Email Validation Bypass Allows Log Injection via Crafted Email Input |
| CVE-2026-81819 | 5.3 MEDIUM | Flowintel Missing Authorization Allows Regular API Users to View Other Users’ Task Assignm |
| CVE-2026-81814 | 5.1 MEDIUM | Flowintel Stored XSS in Calendar via Malicious Case Title |
| CVE-2026-81753 | 5.1 MEDIUM | Flowintel Stored XSS in Case Notes via Malicious Mermaid Diagram Content |
| CVE-2026-81820 | 5.1 MEDIUM | Flowintel HTML Injection in MISP Case History Timeline via Crafted Object Attributes |
No comments yet