Impact
Flowintel versions prior to the security update contain a broken object‑level authorization flaw (CWE‑639). The flaw allows an authenticated user with editor‑level access to one case to use the task ID of a task from another case to modify, delete, or otherwise manipulate the foreign task. This can result in unauthorized changes to task data, loss of integrity, and potential disruption of case management workflows.
Affected Systems
The vulnerability affects Flowintel (flowintel:flowintel) in versions 3.3.0 and later. Users deploying these versions should inspect whether they are running the patched code that enforces the task‑to‑case relationship.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity impact. Since the user can authenticate and has editor level rights, the attacker does not need elevated privileges or system access. Although EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, the exposed endpoint allows relatively straightforward exploitation by an authorized user with cross‑case access rights.
OpenCVE Enrichment