Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-56272

Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.1%
CVSS Severity
CVSS v3 Score 4.1
Products affected by CVE-2026-56272


Contact Us

Shodan ® - All rights reserved