The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.tenable.com/security/research/tra-2026-23 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-27 15:17
Updated : 2026-03-30 13:26
NVD link : CVE-2026-5022
Mitre link : CVE-2026-5022
CVE.ORG link : CVE-2026-5022
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
