A vulnerability identified as critical has been detected in FlowiseAI Flowise up to 3.1.2. The affected element is an unknown function of the component OAuth2 Credential Endpoints. The manipulation leads to improper authorization.

This vulnerability is traded as CVE-2026-70474. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.