CVE-2026-51897
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
Affected products
n/a · n/a