CVE-2026-81819EPSS p38.4%
CVE-2026-81819CVE-2026-81819
Description
Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyond general API authentication.
As a result, a lower-privileged authenticated user could potentially query another user’s assignment information by supplying that user’s identifier.
The fix changes:
method_decorators = [api_required]
to:
method_decorators = [admin_or_org_admin_required, api_required]
so only administrators or organization administrators can perform cross-user assignment queries.
Version impacted =>3.3.0
Scoring
| EPSS | 0.47% probability of exploitation · percentile 38.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-28 |