CVE-2026-81827
Severity CVSS v4.0:
MEDIUM
Type:
CWE-20
Input Validation
Publication date:
27/08/2026
Last modified:
27/08/2026
Description
Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object.<br />
<br />
<br />
Consequently, malformed attacker-controlled email input could continue through the login process and be written to security-relevant logs. The vulnerable code inserted the supplied email into both a warning log and the custom audit logger. Since CR/LF characters were not escaped, an unauthenticated attacker could potentially inject additional physical log lines or forge misleading log entries.<br />
<br />
The patch corrects the validation call to Email()(form, form.email), changes the standard logging call to parameterized logging, and introduces _sanitize_log_fragment() so carriage returns and line feeds are encoded instead of creating new records.<br />
<br />
Version impacted >=3.3.0
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



