CVE-2026-81827

Severity CVSS v4.0:
MEDIUM
Type:
CWE-20 Input Validation
Publication date:
27/08/2026
Last modified:
27/08/2026

Description

Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That does not perform WTForms field validation; it merely constructs a validator object.<br /> <br /> <br /> Consequently, malformed attacker-controlled email input could continue through the login process and be written to security-relevant logs. The vulnerable code inserted the supplied email into both a warning log and the custom audit logger. Since CR/LF characters were not escaped, an unauthenticated attacker could potentially inject additional physical log lines or forge misleading log entries.<br /> <br /> The patch corrects the validation call to Email()(form, form.email), changes the standard logging call to parameterized logging, and introduces _sanitize_log_fragment() so carriage returns and line feeds are encoded instead of creating new records.<br /> <br /> Version impacted &gt;=3.3.0