CVE-2026-41276 | FlowiseAI Flowise up to 3.0.x Password Reset Token reset-password resetPassword improper authentication (GHSA-f6hc-c5jr-878p / WID-SEC-2026-1145)
A vulnerability has been found in FlowiseAI Flowise up to 3.0.x and classified as critical. Affected is the function resetPassword of the file /api/v1/account/reset-password of the component Password Reset Token Handler. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2026-41276. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.