CVE-2026-81817
Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/08/2026
Última modificación:
28/08/2026
Descripción
*** Pendiente de traducción *** Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints.<br />
<br />
<br />
The routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task actually belonged to the supplied case. As a result, an authenticated user with editor-level access to one case could potentially substitute the ID of a task from another case and invoke operations against that foreign task.<br />
<br />
<br />
The patch introduces task_case_bound_required, which loads both objects and returns 404 unless the task belongs to the requested case. This protection is applied to edit, delete, note, assignment, status, file, export, MISP-linking, subtask, external-reference, and other task-related endpoints.<br />
<br />
The fix also adds explicit checks that a requested note_id belongs to the current task before returning or exporting it, closing related cross-object access paths.<br />
<br />
Version impacted =>3.3.0
Impacto
Puntuación base 4.0
7.20
Gravedad 4.0
ALTA



