CVE-2026-81817
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints.<br />
<br />
<br />
The routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task actually belonged to the supplied case. As a result, an authenticated user with editor-level access to one case could potentially substitute the ID of a task from another case and invoke operations against that foreign task.<br />
<br />
<br />
The patch introduces task_case_bound_required, which loads both objects and returns 404 unless the task belongs to the requested case. This protection is applied to edit, delete, note, assignment, status, file, export, MISP-linking, subtask, external-reference, and other task-related endpoints.<br />
<br />
The fix also adds explicit checks that a requested note_id belongs to the current task before returning or exporting it, closing related cross-object access paths.<br />
<br />
Version impacted =>3.3.0
Impact
Base Score 4.0
7.20
Severity 4.0
HIGH



