CVE-2026-56278
Last modified
CVE-2026-56278 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible in the source code, an attacker can forge valid signed session cookies to impersonate any user and bypass authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flowiseai | Flowise | < 3.1.0 |
References
- https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-2qqc-p94c-hxwhMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56278?
How severe is CVE-2026-56278?
How do I fix CVE-2026-56278?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56272Flowise before 3.0.13 uses bcrypt with default salt rounds o…5.6
- CVE-2026-56273Flowise before 3.1.0 contains a path traversal vulnerability…6.5
- CVE-2026-56274Flowise before 3.1.2 contains multiple OS command injection …9.9
- CVE-2026-56275Flowise before 3.1.0 contains a server-side request forgery …7.1
- CVE-2026-56276Flowise before 3.1.2 contains a mass assignment vulnerabilit…6
- CVE-2026-56277Flowise before 3.1.2 sets Access-Control-Allow-Origin to a h…6.5
- CVE-2026-56279Capgo before 12.128.2 contains an information disclosure vul…8.7
- CVE-2026-5628A security vulnerability has been detected in Belkin F9K1015…8.8
- CVE-2026-56280Cap-go before 12.128.2 contains a privilege inversion vulner…7.1
- CVE-2026-56281Capgo before 12.128.2 contains a sql injection vulnerability…3.8
- CVE-2026-56282Capgo before 12.128.2 contains an information disclosure vul…6.9
- CVE-2026-56283Capgo before 12.128.2 contains an html injection vulnerabili…5.4
Are you affected by CVE-2026-56278?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
