CVE 2.3 LOW

Flowsint: Broken Access Control allows modification of investigation metadata from any user_CVE-2026-42158

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Description

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability is fixed in 1.2.3.

Basic Information

ID CVE-2026-42158
Source GitHub_M
Published May 12, 2026 at 23:01

Affected Product

Vendor reconurge
Product flowsint
Version < 1.2.3
Affected Versions reconurge flowsint < 1.2.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.