{"id":"CVE-2026-81817","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-81817","summary":"Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints.\n\n\nThe routes generally received…","details":"Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints.\n\n\nThe routes generally received both a case identifier and a task identifier, but previously they did not enforce that the task actually belonged to the supplied case. As a result, an authenticated user with editor-level access to one case could potentially substitute the ID of a task from another case and invoke operations against that foreign task.\n\n\nThe patch introduces task_case_bound_required, which loads both objects and returns 404 unless the task belongs to the requested case. This protection is applied to edit, delete, note, assignment, status, file, export, MISP-linking, subtask, external-reference, and other task-related endpoints.\n\nThe fix also adds explicit checks that a requested note_id belongs to the current task before returning or exporting it, closing related cross-object access paths.\n\nVersion impacted =>3.3.0","published":"2026-08-27T17:21:05.207","modified":"2026-08-27T17:21:05.207","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/flowintel/flowintel/commit/10676eec7f1286d7ee0769546c772c5cb9c1c72b.patch","label":"flowintel/flowintel@10676ee"},"references":[{"type":"WEB","url":"https://github.com/flowintel/flowintel/commit/10676eec7f1286d7ee0769546c772c5cb9c1c72b.patch"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T17:21:05.207"}}