#VU125535 Unverified Password Change in Flowise
Published: April 9, 2026
Flowise
FlowiseAI
Description
The vulnerability allows a remote user to take over accounts.
The vulnerability exists due to unverified credential change in the account profile email change functionality when updating the account email address. A remote user can change the email address associated with an account without confirming the current password to take over accounts.
The changed email address can be used as a login identifier or password recovery channel.