CVE-2026-33879
CWE-307Published: March 27, 2026· Updated: Mar 30, 2026
Official Description
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.
Technical Analysis
CVE-2026-33879 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (1)
Quick Facts
Related CVEs (CWE-307)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2026-33879 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts