CVE-2026-81817

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
27/08/2026

Description

Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints.<br /> <br /> <br /> The routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task actually belonged to the supplied case. As a result, an authenticated user with editor-level access to one case could potentially substitute the ID of a task from another case and invoke operations against that foreign task.<br /> <br /> <br /> The patch introduces task_case_bound_required, which loads both objects and returns 404 unless the task belongs to the requested case. This protection is applied to edit, delete, note, assignment, status, file, export, MISP-linking, subtask, external-reference, and other task-related endpoints.<br /> <br /> The fix also adds explicit checks that a requested note_id belongs to the current task before returning or exporting it, closing related cross-object access paths.<br /> <br /> Version impacted =&gt;3.3.0