CVE-2026-51893 - RAGFlow Incorrect Access Control Vulnerability
CVE ID :CVE-2026-51893
Published : Oct. 1, 2026, 10:17 p.m. | 56 minutes ago
Description :infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 1, 2026, 10:17 p.m. | 56 minutes ago
Description :infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...