Junglewise Threat Intelligence

CVE-2026-81827: Flowintel login email validation bypass leading to log injection

CVE-2026-81827 · Severity: info · Published 2026-08-27

Technologies: FlowIntel. Vendors: FlowIntel.

Executive brief

Flowintel, an intelligence management platform, failed to properly validate email addresses during login. Because validation was not enforced, attackers could submit malformed email input containing line-break characters that would be written directly to security audit logs without sanitization. This could allow attackers to forge or inject fake log entries, making it difficult to track actual security events and potentially covering unauthorized access attempts.

Technical details

The vulnerability is a log injection flaw caused by improper email validation on the login endpoint. The application called Email(email) to construct a WTForms validator object, but did not actually invoke the validation logic—it merely instantiated the object without executing it. As a result, malformed attacker-controlled email input bypassed validation and reached the logging layer. Since carriage return and line feed characters were not escaped, unauthenticated attackers could inject CR/LF sequences into both standard warning logs and the custom audit logger, creating new log lines or forging misleading entries. The fix corrects the validator invocation to Email()(form, form.email), switches to parameterized logging, and adds _sanitize_log_fragment() to encode line breaks. No network or authentication requirements exist; the flaw is reachable unauthenticated at the login endpoint.

Affected products

  • Flowintel Flowintel >=3.3.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Commit 660b4cc introduces fix with corrected validator invocation and log sanitization

References

Related threats