{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/flowforms--1.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:flowforms:flowforms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":4.3,"id":"CVE-2026-12400"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FlowForms (\u003c= 1.1.1)"],"_cs_severities":["medium"],"_cs_tags":["idor","web-vulnerability","flowforms","cve-2026-12400"],"_cs_type":"threat","_cs_vendors":["FlowForms"],"content_html":"\u003cp\u003eFlowForms versions 1.1.1 and earlier contain an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-12400) within the REST API endpoint responsible for form management. The vulnerability resides in the path /flowforms/v1/forms/{id}, where the system fails to adequately validate the authorization level of the requesting user against the requested form ID. An attacker with a low-privileged account, such as a contributor, can manipulate the ID parameter in the request to modify forms they are not authorized to access or manage. A proof-of-concept exploit is publicly available, increasing the likelihood of exploitation by actors seeking to alter form content or disrupt organizational workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to perform unauthorized modifications to forms within the FlowForms application. This can lead to data integrity issues, unauthorized data collection via modified input fields, or workflow disruption. The impact is limited to the application scope, but poses a significant risk to organizations relying on FlowForms for internal or public-facing data collection.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FlowForms to a version beyond 1.1.1 immediately to remediate CVE-2026-12400.\u003c/li\u003e\n\u003cli\u003eReview user permission assignments to ensure that accounts with contributor-level access are strictly limited to necessary form modification scopes.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous patterns of repeated POST or PUT requests to the /flowforms/v1/forms/ endpoint originating from low-privileged user accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T06:27:09Z","date_published":"2026-09-15T06:27:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-flowforms-idor/","summary":"An authenticated Insecure Direct Object Reference (IDOR) vulnerability in FlowForms version 1.1.1 and earlier allows attackers with contributor-level access to modify arbitrary forms.","title":"Authenticated IDOR Vulnerability in FlowForms","url":"https://feed.craftedsignal.io/briefs/2026-09-flowforms-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - FlowForms (\u003c= 1.1.1)","version":"https://jsonfeed.org/version/1.1"}