CVE-2026-33879 affects Federated Learning and Interoperability Platform (FLIP) versions 0.1.1 and prior, stemming from a lack of rate limiting and CAPTCHA on its login page, which facilitates brute-force and credential-stuffing attacks. With a CVSSv4 score of 2.7 (LOW), this vulnerability presents a network attack vector with low complexity, allowing unauthenticated attackers to attempt unauthorized access to user accounts. The potential impact is unauthorized access, heightened by the risk of credential reuse among FLIP's external user base. There is currently no evidence of active exploitation, no public exploit code, and minimal community discussion or media coverage, though a patch is not yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1CPE matchmatch criteria | cpe:2.3:a:aicentre:federated_learning_and_interoperability_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.