Every story tagged Oauth2, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
2 stories · open in the command center
CVE-2026-70474 is a critical authorization flaw in Flowise (an LLM workflow platform) versions prior to 3.1.3 that allows both authenticated and unauthenticated attackers to hijack OAuth2 credentials across workspaces, potentially compromising connected third-party integrations and sensitive data flows. Organizations using Flowise for AI/LLM operations face immediate risk of unauthorized access to external service credentials and token theft without proper workspace isolation controls. This vulnerability underscores the need for IT organizations to audit their LLM infrastructure dependencies and implement stringent access controls around AI application platforms that handle external authentication.
CVE-2026-69250 is a critical vulnerability (CVSS 8.5) in Flowise versions prior to 3.1.3 that allows unauthenticated attackers with high privileges to bypass authorization and perform server-side request forgery (SSRF) attacks, potentially exposing OAuth2 credentials and sensitive token information. Organizations using Flowise for LLM workflow orchestration face immediate risks of credential theft and unauthorized access to downstream systems. This vulnerability underscores the need for IT organizations to establish robust patch management protocols for AI/ML tools and implement network segmentation to limit lateral movement from compromised LLM platforms.