Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be returned, but previously had no role restriction beyond general API authentication.
As a result, a lower-privileged authenticated user could potentially query another user’s assignment information by supplying that user’s identifier.
The fix changes:
method_decorators = [api_required]
to:
method_decorators = [admin_or_org_admin_required, api_required]
so only administrators or organization administrators can perform cross-user assignment queries.
Version impacted =>3.3.0
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-27 17:21
Updated : 2026-08-28 15:28
NVD link : CVE-2026-81819
Mitre link : CVE-2026-81819
CVE.ORG link : CVE-2026-81819
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
